CVE-2026-86669: aircheng-org iWebShop-5 systemseller.php login improper authentication
A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
aircheng-org iWebShop-5 versions up to and including 5.15 are affected, specifically the Login function in controllers/systemseller.php.
What does an attacker need to exploit this issue?
The attack can be initiated remotely without authentication or user interaction by manipulating the Name argument processed by the affected login function. A public exploit is available.
Is a vendor fix available?
The available information does not identify a fix. The project was notified through an issue report but had not responded at the time of publication.