Junglewise Threat Intelligence

CVE-2026-14161: Advantech Hospital Queuing Management sensitive data exposure in API documentation

CVE-2026-14161 · Severity: high · CVSS 7.5 · Published 2026-06-30

Vendors: Advantech.

Executive brief

Advantech Hospital Queuing Management, a system used to manage patient flow and appointments in healthcare facilities, contains a security flaw that exposes internal technical documentation. An unauthorized person could access detailed API documentation by visiting a specific web address without needing a password. This information could be used by attackers to better understand the system's inner workings and plan more sophisticated attacks against the hospital's infrastructure.

Technical details

Advantech Hospital Queuing Management (HQM) ISO versions prior to 1.2.13 suffer from an information disclosure vulnerability (CWE-200). The application fails to restrict access to internal API documentation, which is reachable via a specific, predictable URL. An unauthenticated remote attacker can access this documentation without any user interaction. This exposure provides attackers with detailed knowledge of the system's API endpoints and data structures, potentially facilitating further attacks such as those leveraging missing authentication in other components. The issue is resolved by updating the HQM ISO to version 1.2.13 or updating QueueHttp.dll to version 1.2.12.7.

Affected products

  • Advantech Hospital Queuing Management (HQM) ISO before 1.2.13

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: disclosed

References