CVE-2026-42515Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API request URL to gain unauthorized access to sensitive information of patients on the targeted system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-29); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-29: 2Mentions · 2026-04-30: 104-2904-30
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure1General1
2026-04-301
Disclosure1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-42515 📊 Severity: 7.1 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42515 #CVE-2026-42515 #CVE #High #CyberSecurity #InfoSec https://t.co/RyHh4lRmH2

    Post summary

    The tweet announces CVE-2026-42515 with a high severity rating but provides no further technical details, PoC, or exploitation evidence.

    0000035
    143 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42515 This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by man… https://www.cve.org/CVERecord?id=CVE-2026-42515

    Post summary

    The text announces CVE-2026-42515, noting improper access control in e‑Sushrut but provides no exploit, patch, or detailed technical data.

    00000122
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42515 Unauthorized Patient Data Access via Parameter Manipulation in e-Sushrut API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42515

    Post summary

    The text identifies CVE‑2026‑42515 and provides a title and a link to a vulnerability details page, but supplies no technical, exploitation, or mitigation information.

    0000039
    4.0K followersView on X

Explore more