Executive brief
Thermo Fisher Scientific Torrent Suite Dx, a software platform used for managing genomic sequencing data, contains a security flaw that allows standard users to gain administrative control. An employee or other authorized user with low-level access could exploit specific system interfaces to take over the entire system. This could lead to unauthorized access to sensitive medical data, modification of sequencing results, or disruption of laboratory operations.
Technical details
A privilege escalation vulnerability (CWE-269) exists in Thermo Fisher Scientific Torrent Suite Dx versions up to and including 5.14.2. The flaw is located within specific system interfaces that fail to properly enforce privilege boundaries. An attacker must be authenticated with low-level user permissions to exploit this vulnerability over the network. Successful exploitation allows the attacker to elevate their privileges to an administrative level, granting full control over the application's data and configuration. The vulnerability has a CVSS 3.1 base score of 8.8, reflecting high impact on confidentiality, integrity, and availability.
Affected products
- Thermo Fisher Scientific Torrent Suite Dx through 5.14.2
Timeline
- 2026-05-18: disclosed
- 2026-05-18: advisory