CVE-2025-15581: Orthanc-Server Orthanc
Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.
Affected products
- Orthanc-Server Orthanc: up to and including 1.12.9
Published 2026-02-18. Last modified 2026-06-17.