Orthanc DICOM Server
Summary
A critical vulnerability, CVE-2026-87020, has been identified in Orthanc DICOM Server versions prior to 1.13.0. Successful exploitation allows an authenticated remote attacker to cause a denial-of-service condition by writing past the end of a heap allocation when processing specially crafted PNG or JPEG images.
IFF Assessment
The vulnerability allows for a denial-of-service condition, which is detrimental to the availability of the targeted system.
Severity
The CVSS v3.1 score of 8.1 (HIGH) is based on an attack vector of Network (AV:N), low complexity (AC:L), requiring privileges (PR:L), no user interaction (UI:N), unchanged scope (S:U), with no confidentiality impact (C:N), high integrity impact (I:H), and high availability impact (A:H), indicating a significant risk.
Defender Context
This vulnerability affects the healthcare sector, a critical infrastructure, and can lead to a denial-of-service, impacting patient care. Defenders should prioritize patching or implementing mitigations for Orthanc DICOM Server deployments, and be aware of potential attacks targeting medical imaging systems.