THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86262 (HIGH 7.3) — A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler

[NVD] CVE-2026-86262 (HIGH 7.3) — A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler

mednvdPublished 2026-09-07

CVE-2026-86262 CVSS: 7.3 HIGH Published: 2026-09-07T03:17:18.893

A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler. The manipulation of the argument userID/id leads to

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86262