CVE-2025-15581
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-15581 is an authorization logic flaw in Orthanc's HTTP Basic Authentication implementation that allows privilege escalation to full administrative access. It affects Orthanc versions before 1.12.10. The vulnerability was published on February 18, 2026, with a Debian LTS advisory issued shortly after. It carries a CVSS v4.0 base score of 4.7 (Medium), though the overall category estimate is rated HIGH due to the potential for full administrative compromise (Red Hat CVE, Feedly).

Technical details

The root cause is classified as CWE-287 (Improper Authentication), specifically an authorization logic flaw in how Orthanc processes HTTP Basic Authentication credentials. The flaw allows an authenticated low-privileged user to bypass access controls and escalate privileges to administrative level. Exploitation requires network access, low initial privileges, and some user interaction (active), with attack requirements present — meaning specific conditions must exist for exploitation. A proof-of-concept has been noted as available (Red Hat CVE, Infinitsec Write-up).

Impact

Successful exploitation allows a low-privileged attacker to escalate to full administrative access within the Orthanc DICOM server, a medical imaging platform. This could expose sensitive patient medical imaging data (DICOM files), allow unauthorized modification or deletion of medical records, and potentially enable further lateral movement within healthcare network environments. The confidentiality impact is rated HIGH for the vulnerable component, making this particularly serious in healthcare and clinical settings where Orthanc is commonly deployed (Red Hat CVE, Feedly).

Exploitability

A proof-of-concept exploit has been noted (CVSS v4.0 exploit maturity: PROOF_OF_CONCEPT), though no confirmed in-the-wild exploitation has been reported at this time. The EPSS score is 0.024% (0.000240), indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Tenable Nessus (plugin IDs 299598 and 300553) and Qualys (detection ID 6274289) (Tenable, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Orthanc DICOM server instances running versions prior to 1.12.10, using tools like Shodan (searching for Orthanc HTTP endpoints, typically on port 8042).
  2. Obtain low-privileged credentials: Acquire or register a low-privileged user account on the target Orthanc instance, or leverage default/weak credentials if present.
  3. Craft malicious HTTP Basic Authentication request: Send a specially crafted HTTP request exploiting the authorization logic flaw in the Basic Authentication handler to manipulate privilege evaluation.
  4. Bypass authorization controls: The flawed authorization logic fails to correctly validate the privilege level, granting the attacker administrative-level access despite only providing low-privileged credentials.
  5. Achieve administrative access: With full admin privileges, the attacker can access all DICOM studies, modify or delete patient data, alter server configuration, or use the Orthanc REST API to pivot further within the network (Infinitsec Write-up, Red Hat CVE).

Indicators of compromise

  • Network: Unusual HTTP requests to the Orthanc REST API (default port 8042) from low-privileged user accounts accessing administrative endpoints (e.g., /system, /tools, /plugins); unexpected administrative API calls following Basic Authentication with non-admin credentials.
  • Logs: Orthanc access logs showing low-privileged user accounts successfully accessing admin-only REST API endpoints; repeated authentication attempts followed by successful privileged operations from the same source IP.
  • Application Behavior: Unexpected configuration changes, new user account creation, or bulk DICOM data access/export initiated by non-administrative user accounts.
  • Scanner Alerts: Triggers on Tenable Nessus plugin IDs 299598 or 300553, or Qualys detection ID 6274289 indicating a vulnerable Orthanc version is present (Tenable, Feedly).

Mitigation and workarounds

Upgrade Orthanc to version 1.12.10 or later, which contains the fix for the authorization logic flaw. Organizations unable to immediately upgrade should restrict network access to the Orthanc HTTP interface (default port 8042) using firewall rules, limiting access to trusted hosts only. Additionally, disabling HTTP Basic Authentication in favor of more robust authentication mechanisms, or placing Orthanc behind a reverse proxy with enforced access controls, can reduce exposure. A Debian LTS security update has also been issued for affected Debian packages (Debian LTS Announce, Red Hat CVE).

Community reactions

Red Hat published a CVE advisory tracking the vulnerability, and Debian issued a Long Term Support (LTS) security announcement (DLA-4494-1) addressing the flaw in packaged versions of Orthanc. A technical write-up was published by Infinitsec detailing the authorization logic flaw. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability tracking and scanner detection updates (Red Hat CVE, Debian LTS Announce, Infinitsec Write-up).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45699HIGH7.5
  • Linux Debian logoLinux Debian
  • netatalk
NoYesAug 14, 2026
CVE-2026-73051MEDIUM6.3
  • Linux Debian logoLinux Debian
  • rust-actix-http
NoYesAug 14, 2026
CVE-2026-47766MEDIUM5.1
  • Linux Debian logoLinux Debian
  • crun
NoYesAug 14, 2026
CVE-2026-47192LOW2.1
  • Python logoPython
  • kas
NoYesAug 14, 2026
CVE-2026-47191LOW2.1
  • Python logoPython
  • kas
NoYesAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management