CVE-2025-15581

MEDIUM

Orthanc <1.12.10 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

Scores

CVSS v4 4.7
EPSS 0.0004
EPSS Percentile 13.6%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
orthanc-server/orthanc < 1.12.9
Published Feb 18, 2026
Tracked Since Feb 19, 2026