CVE-2026-10528

LOW

Orthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow

Title source: cna
STIX 2.1

Description

A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp of the component DCMTK Parser. Performing a manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named bae99026ca97. To fix this issue, it is recommended to deploy a patch.

References (8)

Core 8
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-367636 | Orthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow
https://vuldb.com/vuln/367636
Signature, Permissions Required signature permissions-required
VDB-367636 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/367636/cti
Third Party Advisory third-party-advisory
CVE-2026-10528 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-10528
Third Party Advisory third-party-advisory
Submit #820766 | orthanc orthanc core ≤ 1.12.11 Denial of Service
https://vuldb.com/submit/820766

Scores

CVSS v3 3.3
EPSS 0.0001
EPSS Percentile 2.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-121
Status published
Products (12)
Orthanc/DICOM Server 1.12.0
Orthanc/DICOM Server 1.12.1
Orthanc/DICOM Server 1.12.10
Orthanc/DICOM Server 1.12.11
Orthanc/DICOM Server 1.12.2
Orthanc/DICOM Server 1.12.3
Orthanc/DICOM Server 1.12.4
Orthanc/DICOM Server 1.12.5
Orthanc/DICOM Server 1.12.6
Orthanc/DICOM Server 1.12.7
... and 2 more
Published Jun 02, 2026
Tracked Since Jun 02, 2026