CVE-2026-96548 Details
Description
A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possible to initiate the attack remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability exists in the Sfturing Hosp_Order project, specifically in commit 627f426331da8086ce8fff2017d65b1ddef384f8. The issue arises from hard-coded database and SMTP credentials in the application's resource files. This flaw allows remote access to these sensitive credentials, which the application uses at runtime. The vulnerability's complexity is high, and while the exploit has been published, its actual use remains uncertain.
Credentials should be revoked and rotated, and secrets removed from the repository. It's recommended to use a secret manager or environment variables for sensitive information, apply least-privilege principles for database access, and implement secret-scanning in the continuous integration process.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sfturing/hosp_order/ | [email protected] | ProductVendor |
| https://github.com/sfturing/hosp_order/issues/119 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-96548 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/907904 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/408950 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/408950/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-259 | Use of Hard-coded Password | [email protected] |
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sfturing hosp_order | 627f426331da8086ce8fff2017d65b1ddef384f8 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | New CVE Received | [email protected] |
| Sep 23, 2026 | CVE Modified | CISA-ADP |
Volerion