A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used.
CVE-2026-86262 is a medium-severity vulnerability affecting the Order Handler component of sfturing hosp_order up to version 627f426331da8086ce8fff2017d65b1ddef384f8. The vulnerability allows for authorization bypass through manipulation of the userID or id argument in the updateOrderSta1 or updateOrderdiseaseInfo functions within the OrderController.java file. This issue can be exploited remotely and has [truncated]
A weakness in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8 allows for authorization bypass via manipulation of the userIdenf argument in OrderController.java. The attack can be executed remotely. A public exploit is available. This product uses a rolling release, so version information for affected or updated releases is unavailable.
CVE-2026-86260 is a security flaw in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8, specifically in the modifyPassWord function of CommonUserController.java, allowing unverified password changes. Remote exploitation is possible. The project follows a rolling release approach, so version details for affected or updated releases are not provided.