4.7
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Description
Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation.
Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.
Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.
Basic Information
ID
CVE-2025-15581
Source
PRJBLK
Published
Feb 18, 2026 at 22:59
Modified
Feb 18, 2026 at 23:03
Affected Product
Vendor
orthanc-server
Product
orthanc
Affected Versions
orthanc-server orthanc 0