CVE-2026-82181
Deferred Deferred - Pending Action

Sensitive Data Exposure in Le-yan Medical Practice Management System

Vulnerability report for CVE-2026-82181, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: TWCERT/CC

Description

Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-08-29
AI Q&A
2026-08-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
樂衍有限公司 樂晴醫事管理系統 From 2.4.2.8 (inc) to 2.5.1.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-598 The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Medical Practice Management System by Le-yan has a vulnerability where sensitive data is exposed in URLs. Unauthenticated remote attackers can access this data through a victim's browser history or log files.

Detection Guidance

This CVE describes a Sensitive Data in URL vulnerability in Le-yan Medical Practice Management System. To detect it, inspect web server logs for URLs containing sensitive data like session tokens or credentials. Check browser history or proxy logs for exposed sensitive information in URLs. No specific commands are provided in the context.

Impact Analysis

Attackers may steal sensitive information like passwords or patient data by exploiting browser history or logs. This could lead to identity theft, financial loss, or privacy breaches for users of the system.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to sensitive data. Organizations using the system may face legal penalties, fines, and reputational damage for non-compliance.

Mitigation Strategies

Update the Medical Practice Management System developed by Le-yan to version 2.5.2.0 or later to address the Sensitive Data in URL vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82181. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart