Junglewise Threat Intelligence

CVE-2026-49120: Medplum SSRF in subscription worker

CVE-2026-49120 · Severity: high · CVSS 8.5 · Published 2026-06-02

Executive brief

Medplum is an open-source healthcare platform used to manage patient data and clinical workflows. A security flaw in its subscription system allows authorized users to trick the server into making unauthorized requests to internal systems. This could lead to the theft of sensitive patient health records or administrative credentials from the underlying cloud infrastructure.

Technical details

A server-side request forgery (SSRF) vulnerability exists in the Medplum subscription worker component. The root cause is insufficient validation of endpoint URLs when creating FHIR Subscription resources, allowing authenticated users to specify arbitrary internal addresses. An attacker can exploit this by pointing subscription endpoints at internal services such as cloud metadata services (IMDS), internal databases, or container orchestration APIs. Because the subscription worker sends full FHIR resource payloads in the POST body to these endpoints, it can be used to exfiltrate sensitive patient data or IAM credentials to internal or external locations. The vulnerability is mitigated in version 5.1.14 by requiring HTTPS for rest-hook Subscription URLs by default.

Affected products

  • Medplum Medplum < 5.1.14

Timeline

  • 2026-05-29: patched: Pull request to require HTTPS for rest-hooks merged.
  • 2026-06-01: advisory: Version 5.1.14 released.
  • 2026-06-02: disclosed: CVE published.

References

Related threats