CVE-2026-105382
Received Received - Intake

Improper Authorization in onetwothreeneth HospitalManagementSystem

Vulnerability report for CVE-2026-105382, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A flaw has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function update_subaccount of the file php/controller.php of the component Account Administration. This manipulation of the argument user_id causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
onetwothreeneth HospitalManagementSystem 9ef91ed6007314b6473110ed699dff76d158f61d

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper authorization flaw in the HospitalManagementSystem. The update_subaccount function in php/controller.php allows any user, including unauthenticated attackers, to modify account details like user_id without proper checks. This enables vertical privilege escalation where attackers can take over the admin account by resetting its password and gaining full system access.

Detection Guidance

Check for unauthorized POST requests to the update_subaccount endpoint in php/controller.php. Monitor for unexpected admin password changes or account modifications. Review server logs for requests to /php/controller.php with user_id=1 or admin-related actions.

Impact Analysis

An attacker could exploit this to gain full administrative control over the HospitalManagementSystem. This includes resetting admin passwords, deleting or creating user accounts, modifying hospital data, and potentially uploading malicious files for remote code execution. The system's confidentiality, integrity, and availability would be severely compromised.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for access controls and data protection. GDPR mandates strict authorization checks and protection of personal data, while HIPAA requires role-based access controls for protected health information. The lack of proper authorization could lead to unauthorized access to sensitive patient data, resulting in regulatory penalties and legal consequences.

Mitigation Strategies

Disable the update_subaccount function in php/controller.php. Implement server-side role and authentication checks for all account modification endpoints. Restrict direct admin account modifications and enforce session validation for sensitive actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105382. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart