Cleartext Storage Vulnerability in sfturing hosp_order Software
CVE-2026-96549
Key Information:
- Vendor
Sfturing
- Status
- Vendor
- CVE Published:
- 23 September 2026
Badges
What is CVE-2026-96549?
A vulnerability discovered in the sfturing hosp_order software permits the cleartext storage of sensitive information, exposing critical data to unauthorized local access. This flaw resides within the CommonUserServiceImpl.java file and can be exploited only from a local environment. The vulnerability poses serious security risks as it allows attackers to gain access to confidential information stored in an unprotected format. The development team has been notified of the issue but has yet to issue a public response. This highlights the importance of secure data handling practices and immediate remediation actions to mitigate potential impacts on users.
Affected Version(s)
hosp_order 627f426331da8086ce8fff2017d65b1ddef384f8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
