CVE-2026-14161Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-06-30: 4Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-30: 306-30
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-14161 Sensitive Data Exposure in Advantech Hospital Queuing Management System https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-14161

    Post summary

    The post only lists the CVE identifier and a brief vulnerability title with a link, offering no substantive details or actionable information.

    0000090
    4.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Unauthenticated API documentation exposure in Advantech Hospital Queuing Management (CVE-2026-14161) Advantech Hospital Queuing Management exposes sensitive API documentation via a specific web URL that should not be publicly accessible. The issue stems from improper access control and insecure default exposure of documentation endpoints. An unauthenticated remote attacker can exploit this by directly requesting the documentation URL over the network with no credentials required. If leveraged, this disclosure can accelerate follow-on attacks by revealing endpoints, parameters, and workflows that enable targeted abuse, data access attempts, or service disruption. 👉 Affected: Advantech Hospital Queuing Management (versions not specified) | Upgrade to vendor-fixed version (not specified)

    Post summary

    Advantech Hospital Queuing Management’s API documentation is exposed through a publicly accessible URL, allowing unauthenticated readers to discover endpoints and parameters, with a vendor‑fixed patch available.

    0000055
    232 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14161 Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to … https://www.cve.org/CVERecord?id=CVE-2026-14161 ----- Traducción: CVE-2026-14161 Hos… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-14161 in Advantech Hospital Quening Management as a Sensitive Data Exposure that permits unauthenticated remote attackers to retrieve data via a specific URL.

    0000030
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14161 Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to … https://www.cve.org/CVERecord?id=CVE-2026-14161

    Post summary

    This brief announcement identifies CVE-2026-14161, a sensitive data exposure flaw in Advantech Hospital Quening Management that allows unauthenticated remote attackers to access a specific URL.

    00000674
    57.7K followersView on X

Explore more