Junglewise Threat Intelligence

CVE-2026-86263: sfturing hosp_order authorization bypass in order cancellation

CVE-2026-86263 · Severity: high · CVSS 7.3 · Published 2026-09-07

Technologies: Sfturing Hosp Order. Vendors: Sfturing.

Executive brief

sfturing hosp_order is a hospital appointment scheduling system. An unauthenticated attacker can cancel any patient's appointment by manipulating an order ID parameter, bypassing all authorization checks. This allows unauthorized disruption of medical service scheduling and can trigger cancellation penalties on other patients' accounts.

Technical details

The vulnerability is an authorization bypass (CWE-639: Unverified Ownership) in the OrderController.cancelOrder endpoint (POST /cancelOrder/{id}). The vulnerable component executes the order cancellation immediately via orderRecordsService.cancelOrder(id) before checking if a user exists in the session. No authentication verification or ownership relationship validation occurs—the endpoint processes any numeric ID without verifying the requester's identity or authorization. The attack vector is network-based with no authentication required, no user interaction needed, and no access control preconditions. An attacker can craft a simple HTTP POST request with an arbitrary order ID to cancel any appointment. The project uses a rolling release model and has not yet responded to the early disclosure.

Affected products

  • sfturing hosp_order up to commit 627f426331da8086ce8fff2017d65b1ddef384f8

Timeline

  • 2026-07-22: disclosed: Issue reported on GitHub (#116)
  • 2026-09-07: advisory: CVE-2026-86263 published

References

Related threats