Description
Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML page.
Published: 2026-08-25
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Medical Practice Management System is vulnerable to Remote Code Execution. An unauthenticated attacker can trigger arbitrary operating‑system commands by delivering a specially crafted HTML page to the vulnerable application. This weakness allows the attacker to compromise confidentiality, integrity, and availability of the affected system without any credentials.

Affected Systems

The vulnerability affects Le‑yan Medical Practice Management System. All releases prior to 2.5.2.0 are impacted; the vendor recommends upgrading to version 2.5.2.0 or later to receive the fix.

Risk and Exploitability

The CVSS score of 8.6 indicates a high‑severity flaw. EPSS is not available, and the vulnerability is not listed in CISA KEV, but the lack of authentication requirement and the ability to execute arbitrary commands imply a high likelihood of exploitation for network‑reachable installations. The likely attack vector is remote via the web interface, meaning any system exposed to untrusted traffic is at risk.

Generated by OpenCVE AI on August 25, 2026 at 04:05 UTC.

Remediation

Vendor Solution

Update to version 2.5.2.0 or later


OpenCVE Recommended Actions

  • Upgrade to version 2.5.2.0 or later (the official vendor fix).
  • Enforce network controls such as firewall rules or VPN access to limit who can reach the web interface of the Medical Practice Management System.
  • Disable the vulnerable HTML rendering feature or restrict input tags to prevent execution of arbitrary OS commands.

Generated by OpenCVE AI on August 25, 2026 at 04:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Le-yan
Le-yan medical Practice Management System
Vendors & Products Le-yan
Le-yan medical Practice Management System

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Description Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML page.
Title Le-yan|Medical Practice Management System - Remote Code Execution
Weaknesses CWE-940
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Le-yan Medical Practice Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-08-25T15:23:01.167Z

Reserved: 2026-08-25T01:51:58.792Z

Link: CVE-2026-78685

cve-icon Vulnrichment

Updated: 2026-08-25T15:22:55.355Z

cve-icon NVD

Status : Deferred

Published: 2026-08-25T03:16:58.740

Modified: 2026-08-26T16:40:21.650

Link: CVE-2026-78685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:38:28Z

Weaknesses
  • CWE-940

    Improper Verification of Source of a Communication Channel