Authentication Bypass Vulnerability in e-Sushrut by Third-Party Vendor
CVE-2026-42513

8.8HIGH

What is CVE-2026-42513?

The vulnerability in e-Sushrut arises from flawed authentication logic that inappropriately depends on client-side response parameters. This weakness potentially allows an attacker to intercept and manipulate server responses, enabling them to bypass security measures. By exploiting this flaw, an unauthorized individual could gain entry into user accounts on the system, posing significant security risks.

Affected Version(s)

e-Sushrut, Hospital Management Information System (HMIS) Previous versions

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Harsh Verma
.