CVE-2026-78685
Received Received - Intake

Remote Code Execution in Le-yan Medical Practice Management System

Vulnerability report for CVE-2026-78685, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: TWCERT/CC

Description

Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
le-yan medical_practice_management_system From 2.4.2.8 (inc) to 2.5.1.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-940 The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-78685 is a Remote Code Execution (RCE) vulnerability in the Medical Practice Management System developed by Le-yan. Unauthenticated remote attackers can execute arbitrary OS commands by sending a specially crafted HTML page to vulnerable versions (2.4.2.8 to 2.5.1.9).

Detection Guidance

Detect this vulnerability by checking if your Medical Practice Management System is running versions 2.4.2.8 to 2.5.1.9. Use system commands like 'systemctl status medical_practice_management_system' or check version files in the installation directory. Monitor network traffic for suspicious HTML requests targeting the system.

Impact Analysis

This vulnerability allows attackers to run malicious commands on the system hosting the Medical Practice Management System. This could lead to unauthorized access, data theft, system compromise, or disruption of services. Attackers might install malware, exfiltrate sensitive data, or take control of the system.

Compliance Impact

This RCE vulnerability could lead to breaches of sensitive patient or medical data, violating GDPR and HIPAA requirements. Organizations may face legal penalties, loss of trust, and reputational damage due to non-compliance with data protection regulations.

Mitigation Strategies

Immediately update the Medical Practice Management System to version 2.5.2.0 or later. Isolate affected systems from the network if updates cannot be applied promptly. Disable unnecessary services and restrict access to the system until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78685. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart