
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15581 is an authorization logic flaw in Orthanc's HTTP Basic Authentication implementation that allows privilege escalation to full administrative access. It affects Orthanc versions before 1.12.10. The vulnerability was published on February 18, 2026, with a Debian LTS advisory issued shortly after. It carries a CVSS v4.0 base score of 4.7 (Medium), though the overall category estimate is rated HIGH due to the potential for full administrative compromise (Red Hat CVE, Feedly).
The root cause is classified as CWE-287 (Improper Authentication), specifically an authorization logic flaw in how Orthanc processes HTTP Basic Authentication credentials. The flaw allows an authenticated low-privileged user to bypass access controls and escalate privileges to administrative level. Exploitation requires network access, low initial privileges, and some user interaction (active), with attack requirements present — meaning specific conditions must exist for exploitation. A proof-of-concept has been noted as available (Red Hat CVE, Infinitsec Write-up).
Successful exploitation allows a low-privileged attacker to escalate to full administrative access within the Orthanc DICOM server, a medical imaging platform. This could expose sensitive patient medical imaging data (DICOM files), allow unauthorized modification or deletion of medical records, and potentially enable further lateral movement within healthcare network environments. The confidentiality impact is rated HIGH for the vulnerable component, making this particularly serious in healthcare and clinical settings where Orthanc is commonly deployed (Red Hat CVE, Feedly).
A proof-of-concept exploit has been noted (CVSS v4.0 exploit maturity: PROOF_OF_CONCEPT), though no confirmed in-the-wild exploitation has been reported at this time. The EPSS score is 0.024% (0.000240), indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Tenable Nessus (plugin IDs 299598 and 300553) and Qualys (detection ID 6274289) (Tenable, Feedly).
/system, /tools, /plugins); unexpected administrative API calls following Basic Authentication with non-admin credentials.Upgrade Orthanc to version 1.12.10 or later, which contains the fix for the authorization logic flaw. Organizations unable to immediately upgrade should restrict network access to the Orthanc HTTP interface (default port 8042) using firewall rules, limiting access to trusted hosts only. Additionally, disabling HTTP Basic Authentication in favor of more robust authentication mechanisms, or placing Orthanc behind a reverse proxy with enforced access controls, can reduce exposure. A Debian LTS security update has also been issued for affected Debian packages (Debian LTS Announce, Red Hat CVE).
Red Hat published a CVE advisory tracking the vulnerability, and Debian issued a Long Term Support (LTS) security announcement (DLA-4494-1) addressing the flaw in packaged versions of Orthanc. A technical write-up was published by Infinitsec detailing the authorization logic flaw. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability tracking and scanner detection updates (Red Hat CVE, Debian LTS Announce, Infinitsec Write-up).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."