CVE-2026-14162Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-06-30); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-06-30: 5Mentions · 2026-07-06: 1Patch / Workaround · 2026-06-30: 2Technical Details · 2026-06-30: 5Technical Details · 2026-07-06: 106-3007-06
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-305
Disclosure3General1Patch1
2026-07-061
Disclosure1
Full discourse6 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-14162 — CVSS 9.8/10 ██████████ Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/ftQKLJb9Sj

    Post summary

    The tweet alerts to a critical CVE‑2026‑14162 in Advantech’s Hospital Queuing Management that exposes sensitive data, with a patch now available.

    1000077
    63 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🏥 CVE-2026-14162: Advantech Hospital Queuing Management exposes API documentation to unauthenticated remote attackers via a specific URL — no credentials needed. CVSS 9.3 critical. Healthcare infrastructure at risk. #ICS #CyberSecurity https://secalerts.co/vulnerability/CVE-2026-14162?utm_campaign=x https://t.co/jqe6TEiPJI

    Post summary

    The post discloses that Advantech Hospital Queuing Management has a critical vulnerability (CVE-2026-14162) allowing unauthenticated remote attackers to access API documentation, with a CVSS score of 9.3.

    0000090
    851 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-14162 Unauthenticated Sensitive Data Exposure in Advantech Hosp... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-14162 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post lists CVE‑2026‑14162 with a brief description of unauthenticated sensitive data exposure and includes links to a vulnerability detail page, but offers no proof‑of‑concept, exploit code, patch information, or evidence of active exploitation.

    0000097
    4.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated API Documentation Exposure in Advantech Hospital Queuing Management (CVE-2026-14162) Advantech Hospital Queuing Management exposes sensitive information because a critical function serving API documentation is reachable without authentication. The root cause is missing authentication/access control on a protected endpoint (improper access control). An unauthenticated remote attacker can simply request a specific URL over the network to retrieve the API documentation, with no credentials required. If exploited, this can disclose internal API structure, endpoints, parameters, and workflows that materially lowers the barrier for follow-on attacks such as targeted exploitation, credential abuse, and broader system compromise. 👉 Affected: Advantech Hospital Queuing Management (versions not specified) | Upgrade to vendor-fixed version (not specified)

    Post summary

    Advantech Hospital Queuing Management suffers a critical unauthenticated API documentation exposure due to missing access controls, allowing attackers to retrieve internal structure and facilitate further exploitation.

    0000060
    232 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14162 Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to … https://www.cve.org/CVERecord?id=CVE-2026-14162 ----- Traducción: CVE-2026-14162 Hos… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-14162, a sensitive‑data‑exposure flaw in Advantech's Hospital Queuing Management that lets unauthenticated remote attackers retrieve data via a specific URL.

    0000037
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14162 Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to … https://www.cve.org/CVERecord?id=CVE-2026-14162

    Post summary

    The text announces CVE-2026-14162 as a sensitive data exposure flaw in Advantech’s Hospital Queuing Management, noting unauthenticated remote URL access, but offers no further exploit or patch details.

    00000691
    57.7K followersView on X

Explore more