CVE-2026-102844
Received Received - Intake

Authorization Bypass in gedelumbung HospitalManagement

Vulnerability report for CVE-2026-102844, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects the function detail of the file application/modules/admin/controllers/laporan_data_pasien.php. Executing a manipulation of the argument id_param can lead to authorization bypass. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gedelumbung hospitalmanagement to c2d45543789a3887067d3915f69d44cfc2cf76a8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) vulnerability in the gedelumbung HospitalManagement system. It allows unauthorized access to patient medical records by manipulating the ID parameter in specific URLs. The system fails to verify if the user is authorized to view the requested patient data, even though they are authenticated as an admin or direktur.

Detection Guidance

Check for unauthorized access to patient records by monitoring requests to endpoints like laporan_data_pasien::detail/<id> or ::cetak_detail/<id>. Look for repeated requests with varying IDs from the same user. Use network traffic analysis tools to detect manipulation of the id_param argument in the URL.

Impact Analysis

An attacker with access to the system could view or print any patient's medical records by changing the ID in the URL. This could lead to unauthorized disclosure of sensitive patient information, including personally identifiable data and clinical records. The impact includes privacy breaches, potential fraud through billing data access, and opportunities for further attacks.

Compliance Impact

This vulnerability violates data protection standards like GDPR and HIPAA by allowing unauthorized access to sensitive patient information. It enables privacy breaches and unauthorized disclosure of personally identifiable information, which are key compliance violations under these regulations.

Mitigation Strategies

Implement proper authorization checks to ensure users can only access records they are permitted to view. Restrict access to sensitive endpoints by verifying user permissions and ownership of data. Temporarily disable the affected endpoints if a patch is unavailable.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102844. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart