← Terug naar overzicht

A vulnerability has been identified in sfturing hosp_order up to commit 627f426331da8086ce8fff2017d65b1ddef384f8. The flaw resides in an unknown function within the OrderController.java file of the Order Controller component. By manipulating the 'userIdenf' argument, an attacker can achieve authorization bypass remotely. The exploit is publicly available, increasing the risk of active exploitation. The product uses a rolling release model, making version tracking difficult. The maintainer was notified via a GitHub issue but has not yet responded. No patch or mitigation has been released at this time.

Affected products

  • sfturing hosp_order

Related CVE's

  • CVE-2026-86261

Categories

  • Identity & Access
  • Web Technologies