CVE-2026-90983: OTP Code Exposure in Hayat Hospital's Hayat Mobile
Published Oct 9, 2026
·Updated
Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass.
This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.
Affected Software
1 affected component
Hayat Health Facilities Hayat Mobile>=3.3.0<3.4.0
Event History
Oct 9, 2026
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which releases need remediation?
Hayat Mobile versions from 3.3.0 up to, but not including, 3.4.0 are affected. Version 3.4.0 is not listed as affected.
2
Does exploiting this issue require credentials or user interaction?
No. The supplied vector indicates network-reachable exploitation with low attack complexity, no privileges required, and no user interaction.
3
What is the likely security impact?
The vulnerability allows authentication bypass and is rated high severity. The vector indicates high confidentiality impact, low integrity impact, and no availability impact.