Junglewise Threat Intelligence

CVE-2026-42251: Kamsoft KS-SOMED hard-coded credentials in update modules

CVE-2026-42251 · Severity: info · CVSS 8.7 · Published 2026-06-01

Executive brief

KS-SOMED is a comprehensive medical management system used by clinics and healthcare facilities to handle patient records, scheduling, and administration. A security flaw was identified where hard-coded credentials allowed unauthorized access to the server used for distributing software updates. An attacker could have used this access to upload malicious files, potentially leading to the distribution of compromised software to client machines, though the vendor has since restricted this access to read-only.

Technical details

A vulnerability exists in the KS-SOMED modules KSPLUPDFTP.exe and ANEKSKLIENT.EXE due to the use of hard-coded credentials (CWE-798). These credentials granted unauthorized network access to an FTP server responsible for hosting application update packages. An attacker could leverage these credentials to gain access to the update repository; while the advisory notes the potential for uploading malicious updates, the vendor has since mitigated the risk by changing the update process and restricting the exposed credentials to read-only access. The vulnerability is addressed in versions newer than 30.00.00.056 and 29.00.02.026 respectively.

Affected products

  • Kamsoft KS-SOMED (KSPLUPDFTP.exe) up to 30.00.00.056
  • Kamsoft KS-SOMED (ANEKSKLIENT.EXE) up to 29.00.02.026

Timeline

  • 2026-06-01: advisory: CVE published by CERT.PL

References