CVE-2026-14162: Advantech|Hospital Quering Management - Missing Authentication
Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantech Hospital Queuing Management (HQM) ISOto a version that resolves this vulnerability.Fixed in 1.2.13 - Upgrade
Upgrade
QueueHttp.dllto a version that resolves this vulnerability.Fixed in 1.2.12.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14162?
The severity of CVE-2026-14162 is critical, with a score of 9.8.
What vulnerability does CVE-2026-14162 describe?
CVE-2026-14162 describes a Missing Authentication vulnerability in Advantech's Hospital Queuing Management that allows unauthenticated access to sensitive API documentation.
How do I fix CVE-2026-14162?
To fix CVE-2026-14162, implement proper authentication mechanisms to restrict access to the sensitive API documentation.
What are the potential impacts of CVE-2026-14162?
The potential impacts of CVE-2026-14162 include unauthorized exposure of sensitive data and information theft.
Can CVE-2026-14162 be exploited remotely?
Yes, CVE-2026-14162 can be exploited remotely by unauthenticated attackers.