CVE-2025-26469: Meddream Pacs Server
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A specially crafted application can decrypt credentials stored in a configuration-related registry key. An attacker can execute a malicious script or application to exploit this vulnerability.
Affected products
- Meddream Pacs Server: version 7.3.2.840 only
Published 2025-07-28. Last modified 2026-06-17.