CVE-2025-15581

Orthanc <1.12.10 - Privilege Escalation

Title source: llm

Description

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

Scores

EPSS 0.0003
EPSS Percentile 9.5%

Classification

CWE
CWE-287
Status draft

Timeline

Published Feb 18, 2026
Tracked Since Feb 19, 2026