CVE-2026-96548: sfturing hosp_order jdbc.properties hard-coded credentials

Published Sep 23, 2026
·
Updated

A flaw has been found in sfturing hosporder up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssmpro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possible to initiate the attack remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

1 affected component
sfturing hosp_order

Event History

Sep 23, 2026
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Jan 26, 58699
Event
via NVD·04:27 AM

Frequently Asked Questions

1

Does exploitation require authentication or local access?

The vulnerability is described as remotely exploitable and requires no privileges or user interaction. Exploitation is rated high complexity and difficult, despite a published exploit being available.

2

How can I determine whether my deployment is affected?

Check whether your deployed source includes ssm_pro/src/main/resources/jdbc.properties and whether it is based on code at or before commit 627f426331da8086ce8fff2017d65b1ddef384f8. The advisory does not provide affected release versions because the project uses a rolling release model.

3

Is a fixed release available?

No affected or updated release versions are identified. The project was reportedly notified through an issue report but had not responded at the time of publication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203