Vulnerabilities & Exploits · Web App Attack

Orthanc Flaws Risk Medical Image Exposure and Remote Code Execution

Orthanc's lightweight, standalone design means a single vulnerable instance can expose sensitive medical images or allow remote code execution, not just cause server crashes. The standard approach of patching the service misses that Orthanc often handles protected health information and supports critical imaging workflows, so compromise impacts patient data confidentiality and availability.

Nine vulnerabilities in Orthanc, including denial of service, information disclosure, and arbitrary code execution, are fixed in version 1.12.11. These flaws stem from insufficient input validation and unsafe memory operations, affecting metadata parsing, decompression, and HTTP request handling. Orthanc's minimal dependencies and standalone nature mean it may be deployed in smaller healthcare or research environments lacking robust monitoring or segmentation.

The presence of remote code execution alongside data leakage risks elevates the urgency for patching exposed Orthanc servers, especially those reachable from the internet. This advisory signals that Orthanc is a recurring target with a broad blast radius, threatening both patient privacy and imaging service continuity beyond a typical server vulnerability.

1 source · Apr 10

CVEs in this update

9 CVEs

0 critical · 0 high · 0 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest EPSS: CVE-2026-5445 · 0.67%

Timeline

Sources

Part of the PlainSec briefing for 2026-04-11

Every edition of this story: Orthanc Flaws Risk Medical Image Exposure and Remote Code Execution

More from today