Improper Authentication Vulnerability in gedelumbung HospitalManagement
CVE-2026-93532
Key Information:
- Vendor
Gedelumbung
- Status
- Vendor
- CVE Published:
- 18 September 2026
Badges
What is CVE-2026-93532?
A vulnerability exists in gedelumbung HospitalManagement that affects its Password Change Handler responsible for managing user password updates. This flaw allows attackers to manipulate user credentials, particularly the 'kode_user' or 'username' parameters, enabling unauthorized access. The issue can be exploited remotely, potentially granting an attacker higher privileges within the system. Despite an early alert about this security risk, there has been no response from the project team to address the problem, increasing the urgency for users to assess their security posture and implement mitigations.
Affected Version(s)
HospitalManagement c2d45543789a3887067d3915f69d44cfc2cf76a8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
