Improper Authentication in innocommerce InnoShop Affects Installation Endpoint
CVE-2026-7630
Key Information:
- Vendor
Innocommerce
- Status
- Vendor
- CVE Published:
- 2 May 2026
Badges
What is CVE-2026-7630?
A vulnerability has been identified in the InnoShop component from innocommerce, specifically in the InstallServiceProvider::boot function within the Installation Endpoint. This flaw allows improper authentication, potentially enabling remote exploitation. The issue has been made public, and users are advised to apply the patch identified by commit 45758e4ec22451ab944ae2ae826b1e70f6450dc9 to remediate the vulnerability and secure their applications.
Affected Version(s)
InnoShop 0.6.*
InnoShop 0.7.0
InnoShop 0.7.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
