VORANT. Threat Intelligence Sign in Get the full feed

mpGabinet flaws chain to unauthenticated RCE

high vulnerability healthcare

Three chained vulnerabilities in BinSoft mpGabinet let an unauthenticated attacker steal admin database credentials, bypass login, and achieve remote code execution.

CERT Polska coordinated disclosure of three vulnerabilities in BinSoft's mpGabinet medical practice management software affecting version 23.12.19 and earlier. CVE-2026-40550 stems from the application using an over-privileged database account whose administrative credentials can be extracted from process memory by anyone with access to a running client instance. CVE-2026-40551 arises because authentication checks are performed client-side, allowing an attacker to patch the application binary and log in as any user. CVE-2026-40552 permits remote command execution by an authorized user who can modify an attachment's storage path in the database to point to an attacker-controlled network resource, which is executed when the attachment is opened.

Individually these issues require some level of access, but the report notes that CVE-2026-40552 can be reached by a fully unauthenticated attacker by chaining all three: extracting admin database credentials via CVE-2026-40550, using them to log in as any user via CVE-2026-40551, and then weaponizing the attachment-path manipulation for code execution. This full chain effectively allows takeover of backend systems running mpGabinet without any prior authentication or privileges, posing a significant risk to healthcare organizations using this practice-management software.

No evidence of active exploitation is mentioned in the advisory; this is a coordinated vulnerability disclosure with credit given to the reporting researchers. Affected organizations should apply vendor updates or mitigations once available and restrict network/database access to mpGabinet backend instances.

Mentioned in this report

Vulnerabilities CVE-2026-40550CVE-2026-40551CVE-2026-40552

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-40550

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free