CVE-2025-53912: Meddream Pacs Server

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file read. An attacker can send http request to trigger this vulnerability.

Affected products

  • Meddream Pacs Server: version 7.3.6.870 only

Published 2026-01-20. Last modified 2026-06-17.