PT-2026-35882 · Cdac Noida · E-Sushrut

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-42514

CVSS v4.0

8.8

High

AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTPs.
Successful exploitation of this vulnerability could allow an attacker to impersonate the target user and gain unauthorized access to user accounts on the targeted system.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2026-42514

Affected Products

E-Sushrut