Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the renderer process to access Node.js APIs and execute arbitrary operating system commands.
References
Configurations
No configuration.
History
20 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-917 |
19 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
18 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-18 15:16
Updated : 2026-05-20 13:16
NVD link : CVE-2026-26462
Mitre link : CVE-2026-26462
CVE.ORG link : CVE-2026-26462
JSON object : View
Products Affected
No product.
CWE
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
