Executive brief
Roche Diagnostics navify Digital Pathology, a platform used for managing pathology workflows and medical imaging, contains a security flaw where the internal message broker (RabbitMQ) is configured with a default username and password. If the system is accessible over the network, an unauthorized person could log into the management dashboard to disrupt internal operations, such as halting data processing or deleting task queues. While no patient data or sensitive personal information is exposed, an exploit could cause significant operational delays and temporary service outages in a clinical environment.
Technical details
The navify Digital Pathology platform (versions 2.0.0 through 2.4.1) is vulnerable to the use of default credentials (CWE-1392) within its RabbitMQ Management interface. By default, the interface is configured with the 'guest:guest' account, which may remain active unless manually changed during installation. A remote, unauthenticated attacker with network access to the RabbitMQ port can gain full administrative access to the message broker dashboard. While the interface does not expose sensitive patient data, it provides the ability to delete queues and inject arbitrary messages. This can lead to a denial-of-service condition by halting the processing of job management, metadata services, and analysis progress tracking. Roche recommends changing the default password and ensuring the server is isolated from public networks.
Affected products
- Roche Diagnostics navify Digital Pathology 2.0.0 to 2.4.1
Timeline
- 2026-05-29: advisory: Initial advisory published by Roche Diagnostics
- 2026-06-02: disclosed: CVE-2026-9844 published to NVD