Junglewise Threat Intelligence

CVE-2026-31071: LalanaChami Pharmacy Management System Authentication Bypass and Privilege Escalation

CVE-2026-31071 · Severity: info · CVSS 9.4 · Published 2026-05-19

Executive brief

The LalanaChami Pharmacy Management System contains a critical security flaw that allows anyone to create an administrative account without a password or existing credentials. This vulnerability also permits unauthorized access to sensitive data, including patient prescriptions, drug inventory, and user account details. An attacker could use this to take full control of the pharmacy's operations, modify inventory records, or steal private medical information.

Technical details

The LalanaChami Pharmacy Management System (commit 5c3d028) suffers from two primary security failures. First, multiple API endpoints (such as /api/user/getUserData and /api/doctorOder) lack authentication middleware, allowing unauthenticated remote attackers to dump user records (including bcrypt hashes), modify drug inventory, and access private medical prescriptions. Second, the /api/user/signup endpoint in backend/routes/user.js fails to validate the 'role' parameter from the request body. An attacker can perform a privilege escalation attack by injecting 'role': 'admin' during registration to gain full administrative access. The vulnerability stems from directly passing user-controlled input into the User model constructor without whitelisting or server-side role assignment.

Affected products

  • LalanaChami Pharmacy Management System commit 5c3d028

Timeline

  • 2026-05-19: disclosed: Vulnerability details and PoC published via GitHub Gist.
  • 2026-05-19: advisory: CVE-2026-31071 published.

References

Related threats