CVE-2026-96552 Overview
CVE-2026-96552 affects the sfturing/hosp_order project, an open-source hospital order management application distributed on GitHub. The vulnerability resides in the MD5.getMD5 function of ssm_pro/src/main/java/cn/sfturing/utils/MD5.java, which handles user password hashing. The implementation applies MD5 without a salt, classifying the flaw as a one-way hash without salt weakness [CWE-325]. The project follows a rolling release model, so fixed version identifiers are not published, and affected code is tracked up to commit 627f426331da8086ce8fff2017d65b1ddef384f8. A public exploit reference exists, though the vendor has not responded to the upstream issue report.
Critical Impact
Unsalted MD5 password hashes exposed through database compromise can be reversed at scale using precomputed rainbow tables, allowing credential recovery and account takeover.
Affected Products
- sfturing/hosp_order up to commit 627f426331da8086ce8fff2017d65b1ddef384f8
- Component: User Password Handler (ssm_pro/src/main/java/cn/sfturing/utils/MD5.java)
- Function: MD5.getMD5
Discovery Timeline
- 2026-09-23 - CVE-2026-96552 published to the National Vulnerability Database
- 2026-09-23 - Entry last modified in NVD
Technical Details for CVE-2026-96552
Vulnerability Analysis
The MD5.getMD5 utility in hosp_order computes a raw MD5 digest of user-supplied passwords with no per-user salt and no key derivation function. Stored hashes are therefore deterministic across users and installations. An attacker who obtains the credential store — through SQL injection, backup exposure, or insider access — can match hashes against precomputed rainbow tables or GPU-accelerated dictionaries and recover plaintext passwords rapidly. The exploit requires low privileges (PR:L) and is network-reachable, but attack complexity is high because it depends on prior access to the hashed credential material.
Root Cause
The root cause is a design-level cryptographic weakness. MD5 is not a password hashing algorithm; it is a general-purpose message digest. Using it without a unique salt violates modern password storage guidance, which requires adaptive functions such as bcrypt, scrypt, Argon2, or PBKDF2 with per-user salts. Without a salt, identical passwords produce identical hashes, enabling bulk cracking and cross-account correlation.
Attack Vector
An attacker with access to the persisted password column extracts the MD5 hashes and runs offline recovery against them. Because MD5 throughput on commodity GPUs exceeds tens of billions of hashes per second, common and moderately complex passwords are recovered in minutes. Recovered credentials are then replayed against the hosp_order application login flow or reused across other systems where password reuse is likely. No exploitation code needs to run inside the application itself; the weakness is realized entirely offline once the hash store is disclosed.
No verified exploit code is published for CVE-2026-96552.
See the VulDB report and the upstream repository for technical context:
https://vuldb.com/cve/CVE-2026-96552
https://github.com/sfturing/hosp_order/
Detection Methods for CVE-2026-96552
Indicators of Compromise
- Presence of the cn.sfturing.utils.MD5 class or calls to MD5.getMD5 in deployed artifacts, indicating vulnerable code paths remain active.
- Password column values that are exactly 32 hexadecimal characters and match well-known MD5 hashes for common passwords (for example, 5f4dcc3b5aa765d61d8327deb882cf99 for password).
- Successful logins from unexpected geographies immediately following any incident involving database backup exposure or unauthorized data export.
Detection Strategies
- Perform static code review of ssm_pro/src/main/java/cn/sfturing/utils/MD5.java and any callers of MD5.getMD5 to confirm the hashing pathway used for credentials.
- Run offline audits against exported hash samples using tools such as hashcat -m 0 to identify weak, unsalted, or reused passwords.
- Instrument authentication endpoints to alert on credential stuffing patterns: high-rate login attempts, distributed source IPs, and elevated failure-to-success ratios.
Monitoring Recommendations
- Forward authentication and database access logs to a centralized analytics platform and baseline normal login volumes per account and per source.
- Alert on bulk reads of tables containing password columns and on any export or dump operation against the user credential store.
- Track new inbound sessions authenticating with credentials that appear in known breach corpora to identify reused or previously cracked passwords.
How to Mitigate CVE-2026-96552
Immediate Actions Required
- Replace MD5.getMD5 with an adaptive password hashing function such as bcrypt, Argon2id, or PBKDF2-HMAC-SHA256 with a per-user random salt of at least 16 bytes.
- Force a password reset for all existing users and rehash new passwords using the replacement algorithm; do not migrate legacy MD5 hashes by wrapping them.
- Restrict direct database access to the credential store and enforce least privilege on the application service account.
Patch Information
The project uses a rolling release model and no fixed version has been published. Maintainers had not responded to the upstream issue at the time of NVD publication. Track the GitHub Issue Tracker and the VulDB CVE Report for remediation status, and rebuild from source once a corrected MD5.java (or its replacement) is committed to the sfturing/hosp_order repository.
Workarounds
- Enforce multi-factor authentication on all hosp_order accounts so that recovered passwords alone do not grant access.
- Apply a server-side pepper stored outside the database and rehash credentials using a modern KDF before the next production deployment.
- Deploy a web application firewall rule set to rate-limit authentication endpoints and block known credential-stuffing infrastructure.
# Example: verify no MD5-based password hashing remains in the codebase
grep -RIn --include='*.java' -e 'MessageDigest.getInstance("MD5")' \
-e 'MD5.getMD5' ssm_pro/src/main/java/
# Example: audit exported hash samples for MD5 usage (32-hex characters)
awk -F',' 'length($2)==32 && $2 ~ /^[0-9a-f]+$/ {print $1}' users_export.csv
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.