Orthanc DICOM Server

Summary

A critical vulnerability, CVE-2026-87020, has been identified in Orthanc DICOM Server versions prior to 1.13.0. Successful exploitation allows an authenticated remote attacker to cause a denial-of-service condition by writing past the end of a heap allocation when processing specially crafted PNG or JPEG images.

IFF Assessment

FOE

The vulnerability allows for a denial-of-service condition, which is detrimental to the availability of the targeted system.

Severity

8.1 High

The CVSS v3.1 score of 8.1 (HIGH) is based on an attack vector of Network (AV:N), low complexity (AC:L), requiring privileges (PR:L), no user interaction (UI:N), unchanged scope (S:U), with no confidentiality impact (C:N), high integrity impact (I:H), and high availability impact (A:H), indicating a significant risk.

Defender Context

This vulnerability affects the healthcare sector, a critical infrastructure, and can lead to a denial-of-service, impacting patient care. Defenders should prioritize patching or implementing mitigations for Orthanc DICOM Server deployments, and be aware of potential attacks targeting medical imaging systems.

Read Full Story →