EIP-2026-119432

PRE-CVE

SonicDICOM PACS 2.3.2 - Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119432. PoCs published by LiquidWorm.

AI-analyzed exploit summary The exploit demonstrates a vertical privilege escalation vulnerability in SonicDICOM PACS 2.3.2 by sending an HTTP PATCH request with the 'Authority' parameter set to '1', granting admin rights to a normal user. The provided HTTP request template is functional and includes all necessary headers and parameters.

Description

SonicDICOM PACS 2.3.2 - Privilege Escalation

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappswindows
https://www.exploit-db.com/exploits/41311

The exploit demonstrates a vertical privilege escalation vulnerability in SonicDICOM PACS 2.3.2 by sending an HTTP PATCH request with the 'Authority' parameter set to '1', granting admin rights to a normal user. The provided HTTP request template is functional and includes all necessary headers and parameters.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: SonicDICOM PACS 2.3.2 and 2.3.1
Auth required
Prerequisites: Valid user session (cookie) · Network access to the target application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026