PicoTronica e-Clinic Healthcare System Missing Authentication Vulnerability in Patient Records API Endpoint

Vulnerability

A vulnerability in PicoTronica e-Clinic Healthcare System version 5.7 has been identified. The issue resides in an unknown function within the file '/cdemos/echs/api/v2/patient-records' of the API Endpoint component. This vulnerability allows for missing authentication, enabling remote exploitation that could lead to unauthorized access to patient records. The exploit is public and has been actively disseminated.

Impact

Exploitation of this vulnerability allows for unauthorized access to patient personally identifiable information (PII) through the patient-records API, which could lead to privacy violations and misuse of sensitive health information.

Remediation

Users are advised to upgrade to version 5.7.1 to address this vulnerability.

Added: May 6, 2026, 7:20 PM
Updated: May 6, 2026, 7:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
7.6
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.