CVE-2026-10528
LOWOrthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow
Title source: cnaDescription
A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp of the component DCMTK Parser. Performing a manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named bae99026ca97. To fix this issue, it is recommended to deploy a patch.
References (8)
Core 8
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-367636 | Orthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow
https://vuldb.com/vuln/367636
Signature, Permissions Required signature
permissions-required
VDB-367636 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/367636/cti
Third Party Advisory third-party-advisory
CVE-2026-10528 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-10528
Third Party Advisory third-party-advisory
Submit #820766 | orthanc orthanc core ≤ 1.12.11 Denial of Service
https://vuldb.com/submit/820766
Issue Tracking issue-tracking
https://orthanc.uclouvain.be/bugs/show_bug.cgi?id=258
Issue Tracking issue-tracking
https://orthanc.uclouvain.be/bugs/show_bug.cgi?id=258#c4
Exploit exploit
https://orthanc.uclouvain.be/bugs/attachment.cgi?id=150
Scores
CVSS v3
3.3
EPSS
0.0001
EPSS Percentile
2.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-119
CWE-121
Status
published
Products (12)
Orthanc/DICOM Server
1.12.0
Orthanc/DICOM Server
1.12.1
Orthanc/DICOM Server
1.12.10
Orthanc/DICOM Server
1.12.11
Orthanc/DICOM Server
1.12.2
Orthanc/DICOM Server
1.12.3
Orthanc/DICOM Server
1.12.4
Orthanc/DICOM Server
1.12.5
Orthanc/DICOM Server
1.12.6
Orthanc/DICOM Server
1.12.7
... and 2 more
Published
Jun 02, 2026
Tracked Since
Jun 02, 2026