Executive brief
OFFIS DCMTK is a widely used toolkit for processing and transmitting medical images and data in healthcare environments. A security flaw allows an unauthorized person to bypass data separation controls and access medical worklist records they should not be able to see. In a hospital or clinic setting, this could lead to the exposure of sensitive patient information across different departments.
Technical details
A path traversal vulnerability (CWE-22) exists in the worklist server component of the OFFIS DCMTK toolkit. An unauthenticated remote attacker can exploit this by submitting crafted requests to access worklist records stored in directories outside the intended per-Application Entity (AE) storage area. In multi-tenant or multi-departmental deployments, this allows for the unauthorized retrieval of sensitive DICOM worklist data across administrative boundaries. The vulnerability affects versions up to and including 3.7.0; a fix has been committed to the project's main repository.
Affected products
- OFFIS DCMTK Toolkit <= 3.7.0
Timeline
- 2026-06-25: patched: Fix included in latest repository commits/snapshots
- 2026-06-30: advisory: CISA ICS Medical Advisory ICSMA-26-181-01 published
- 2026-06-30: disclosed