Authorization Bypass in Sfturing Hosp_Order Order Handler
CVE-2026-86262
Key Information:
- Vendor
Sfturing
- Status
- Vendor
- CVE Published:
- 7 September 2026
Badges
What is CVE-2026-86262?
A significant security flaw has been identified in Sfturing's Hosp_Order software, specifically within the Order Handler component. An attacker can exploit this vulnerability through remote manipulation of the userID/id argument in the updateOrderSta1/updateOrderdiseaseInfo function of OrderController.java. This exploitation allows unauthorized access to sensitive functionalities within the application. Although the vulnerability has been publicly disclosed, and the project maintainers were alerted early through an issue report, there has been no official response or release to mitigate the risk. Users are advised to proceed with caution.
Affected Version(s)
hosp_order 627f426331da8086ce8fff2017d65b1ddef384f8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
