CVE-2025-27724: Meddream Pacs Server
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file can lead to elevated capabilities. An attacker can upload a malicious file to trigger this vulnerability.
Affected products
- Meddream Pacs Server: version 7.3.2.840 only
Published 2025-07-28. Last modified 2026-06-17.