Executive brief
Le-yan's Medical Practice Management System is software used by healthcare providers to manage patient records and clinical operations. An unauthenticated remote attacker can trick a user into visiting a malicious webpage to execute arbitrary system commands on the medical practice's server, potentially leading to data theft, system compromise, and operational disruption of patient care delivery.
Technical details
CVE-2026-78685 is a remote code execution vulnerability in the Medical Practice Management System that allows unauthenticated attackers to execute arbitrary OS commands via a crafted HTML page. The attack requires user interaction—the victim must visit or be socially engineered into visiting a malicious webpage—but does not require prior authentication to the system. The vulnerability achieves high impact across confidentiality, integrity, and availability. A patch is available: users should update to version 2.5.2.0 or later.
Affected products
- Le-yan Medical Practice Management System 2.4.2.8 to 2.5.1.9
Timeline
- 2026-08-25: disclosed