High severity8.2NVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026
CVE-2026-52868
CVE-2026-52868
Description
An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
2- DICOM Toolkit Bugs Raise Medical Imaging Security RisksGovInfoSecurity · Jun 30, 2026
- OFFIS DCMTK ToolkitCISA Alerts