← Back to overview

A security vulnerability has been identified in sfturing hosp_order up to commit 627f426331da8086ce8fff2017d65b1ddef384f8. The vulnerability resides in the updateOrderSta1/updateOrderdiseaseInfo functions within the OrderController.java file of the Order Handler component. Manipulation of the userID/id arguments allows an attacker to bypass authorization controls. The vulnerability can be exploited remotely, and a public exploit has already been disclosed. The project uses a rolling release strategy, making it difficult to specify exact affected or patched versions. The vendor was notified via a GitHub issue report but has not responded. This poses a risk to healthcare order management systems using this software.

Affected products

  • sfturing hosp_order

Related CVE's

  • CVE-2026-86262

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies