Skip to main content
Vulnerability Database/CVE-2026-86261

CVE-2026-86261: sfturing hosp_order Auth Bypass Vulnerability

CVE-2026-86261 is an authorization bypass flaw in sfturing hosp_order OrderController that allows remote attackers to circumvent authentication checks. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-86261 Overview

CVE-2026-86261 is an authorization bypass vulnerability in the sfturing hosp_order project, a hospital order management application. The flaw resides in the OrderController.java file within the ssm_pro/src/main/java/cn/sfturing/web/ path. Attackers can manipulate the userIdenf argument to bypass authorization checks and access resources belonging to other users. The vulnerability is remotely exploitable without authentication or user interaction. A public proof-of-concept exists, and the maintainer has been notified through a GitHub issue but has not responded. Because the project follows a rolling release model, no fixed version identifier is available.

Critical Impact

Remote attackers can bypass authorization controls in the Order Controller by manipulating the userIdenf parameter, gaining unauthorized access to order data across user boundaries.

Affected Products

  • sfturing hosp_order (rolling release)
  • Affected commit range up to 627f426331da8086ce8fff2017d65b1ddef384f8
  • Component: OrderController.java in ssm_pro/src/main/java/cn/sfturing/web/

Discovery Timeline

  • 2026-09-07 - CVE-2026-86261 published to the National Vulnerability Database (NVD)
  • 2026-09-08 - Last updated in NVD database

Technical Details for CVE-2026-86261

Vulnerability Analysis

The vulnerability is classified under [CWE-285] Improper Authorization. It resides in an unspecified function of OrderController.java, part of the Order Controller component in the hosp_order Spring MVC application. The controller accepts a userIdenf argument from the client and uses it to determine which user's data to operate on without verifying that the requester is authorized for that identifier. Attackers can substitute another user's identifier value to read or modify orders that do not belong to them. The attack is executed over the network against exposed HTTP endpoints and requires no prior authentication or user interaction.

Root Cause

The root cause is the controller's reliance on a client-supplied identifier for authorization decisions instead of the authenticated session principal. The application trusts the userIdenf request parameter as a source of identity, allowing an attacker to specify any target user. There is no server-side check binding the parameter value to the authenticated session, session token, or role. This is a classic broken-object-level-authorization pattern in Java Spring MVC controllers.

Attack Vector

An attacker submits an HTTP request to the vulnerable endpoint in OrderController and sets userIdenf to a victim's identifier. The server processes the request in the context of the specified user without validating ownership. The vulnerability affects confidentiality, integrity, and availability at a limited scope, consistent with unauthorized access to order records. See the GitHub PoC Repository and GitHub Issue #114 for reference material.

No verified exploit code is reproduced here. Refer to the VulDB CVE-2026-86261 entry for the public disclosure details.

Detection Methods for CVE-2026-86261

Indicators of Compromise

  • HTTP requests to Order Controller endpoints containing the userIdenf parameter with values that do not match the authenticated session user.
  • Access log entries showing a single session enumerating sequential or varied userIdenf values across short time windows.
  • Application responses returning order records for identifiers not associated with the requesting account.

Detection Strategies

  • Instrument the Spring MVC controller to log both the authenticated principal and the submitted userIdenf value, and alert when they diverge.
  • Deploy web application firewall (WAF) rules to inspect requests to OrderController routes and correlate the userIdenf argument with the session cookie or JWT subject.
  • Perform authenticated dynamic application security testing (DAST) against the hosp_order deployment to detect broken object level authorization flows.

Monitoring Recommendations

  • Baseline normal ratios of unique userIdenf values per session and alert on outliers indicative of enumeration.
  • Monitor for anomalous volumes of successful responses to Order Controller endpoints from a single source IP or session.
  • Forward application access logs to a centralized SIEM to enable correlation across authentication, session, and authorization events.

How to Mitigate CVE-2026-86261

Immediate Actions Required

  • Restrict network exposure of the hosp_order application to trusted internal networks until a patch is available.
  • Add a server-side authorization check in OrderController.java that binds every operation to the authenticated session principal instead of the client-supplied userIdenf.
  • Review application logs for prior exploitation attempts targeting the userIdenf parameter and revoke affected sessions.

Patch Information

No vendor patch is available. The project uses a rolling release model, and the maintainer has not responded to GitHub Issue #114. Operators running the affected commit range up to 627f426331da8086ce8fff2017d65b1ddef384f8 should apply source-level fixes and rebuild from the corrected code. Track the sfturing hosp_order repository for future updates.

Workarounds

  • Modify OrderController.java to derive the user identifier from the authenticated Spring Security Principal or session attribute rather than a request parameter.
  • Introduce a filter or interceptor that rejects requests where the submitted userIdenf does not match the authenticated user's identifier.
  • Place the application behind a reverse proxy or WAF that enforces authentication and inspects request parameters against session identity.
bash
# Example WAF-style pseudo-rule: block requests where userIdenf does not match the session user
# Adapt for your WAF syntax (ModSecurity, NGINX njs, etc.)
SecRule ARGS:userIdenf "!@streq %{SESSION.user_id}" \
    "id:1026862610,phase:2,deny,status:403,log,msg:'CVE-2026-86261 userIdenf mismatch'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.