Cleartext Storage Vulnerability in sfturing hosp_order Software
CVE-2026-96549

4.8MEDIUM

Key Information:

Vendor

Sfturing

Vendor
CVE Published:
23 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-96549?

A vulnerability discovered in the sfturing hosp_order software permits the cleartext storage of sensitive information, exposing critical data to unauthorized local access. This flaw resides within the CommonUserServiceImpl.java file and can be exploited only from a local environment. The vulnerability poses serious security risks as it allows attackers to gain access to confidential information stored in an unprotected format. The development team has been notified of the issue but has yet to issue a public response. This highlights the importance of secure data handling practices and immediate remediation actions to mitigate potential impacts on users.

Affected Version(s)

hosp_order 627f426331da8086ce8fff2017d65b1ddef384f8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

zbzz (VulDB User)
VulDB CNA Team
.