{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/iwebshop--5.15/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:aircheng:iwebshop:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-86665"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["iWebShop (\u003c= 5.15)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","access-control","cve-2026-86665"],"_cs_type":"advisory","_cs_vendors":["aircheng"],"content_html":"\u003cp\u003eA security vulnerability (CVE-2026-86665) has been identified in the iWebShop e-commerce platform, affecting all versions up to and including 5.15. The flaw resides within the Update::index function located in controllers/update.php. This vulnerability is characterized as a missing authorization issue, which can be exploited remotely by unauthenticated actors to interact with functions intended only for administrative users. As this vulnerability affects a core administrative controller, successful exploitation could lead to unauthorized system configuration changes or administrative control over the e-commerce environment. Public exploits are currently available, and the vendor has not yet addressed the issue. Defenders should prioritize restricting network access to the application's administrative and update-related routes to mitigate the risk of remote exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to bypass security controls and perform administrative actions within the iWebShop environment. This could result in unauthorized modification of store configurations, potential data exposure, or complete site takeover, depending on the capabilities exposed by the Update controller.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web access logs for unauthorized POST or GET requests targeting controllers/update.php from non-administrative IP addresses.\u003c/li\u003e\n\u003cli\u003eImplement access control lists at the web server level to restrict access to the /controllers/update.php path, ensuring only authorized administrative management networks can reach this endpoint.\u003c/li\u003e\n\u003cli\u003eAudit existing administrative user accounts and system configuration logs for unexpected changes that may have occurred since the public release of the exploit.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T15:42:05Z","date_published":"2026-09-08T15:42:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-iwebshop-unauth-access/","summary":"A missing authorization vulnerability in the iWebShop Update::index function allows unauthenticated remote attackers to access restricted administrative functions in versions up to 5.15.","title":"Authorization Bypass in iWebShop via Update Controller","url":"https://feed.craftedsignal.io/briefs/2026-09-iwebshop-unauth-access/"}],"language":"en","title":"CraftedSignal Threat Feed - IWebShop (\u003c= 5.15)","version":"https://jsonfeed.org/version/1.1"}