CVE-2026-86665
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/
CVSS
7.3
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-862 · CWE-863
Not enough EPSS history yet.
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-839427.8 HIG—
———Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.3hCVE-2026-839419.9 CRI—
———Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.3hCVE-2026-818235.3 MED—
———The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.3hCVE-2026-730147.8 HIG—
———Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.3hCVE-2026-729665.5 MED—
———Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.3hCVE-2026-702837.0 HIG—
———Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.3h