← Back to overview

A vulnerability was identified in the sfturing hosp_order application up to commit 627f426331da8086ce8fff2017d65b1ddef384f8. The flaw exists in the orderRecordsService.cancelOrder function within OrderController.java, specifically in the Order Cancellation component. Manipulation of the ID argument enables an attacker to bypass authorization controls remotely. A public exploit is already available, increasing the risk of active exploitation. The product uses a rolling release model, so no specific version information is disclosed for affected or patched releases. The project maintainer was notified via an issue report but has not yet responded. This represents an actively exploitable, unpatched authorization bypass in a hospital order management system. The lack of vendor response and public exploit availability significantly elevates the risk level.

Affected products

  • sfturing hosp_order

Related CVE's

  • CVE-2026-86263

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies