VYPR
advisoryPublished Sep 10, 2026· 1 source

CISA Warns of Integer Overflow Vulnerability in Orthanc DICOM Server

CISA has issued an advisory for Orthanc DICOM Server versions prior to 1.13.0, detailing CVE-2026-87020, an integer overflow vulnerability that can lead to a denial-of-service condition.

The Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory highlighting a critical vulnerability affecting the Orthanc DICOM Server, a widely used software for managing medical imaging data. The vulnerability, identified as CVE-2026-87020, impacts all versions of Orthanc DICOM Server prior to 1.13.0.

This vulnerability stems from an integer overflow or wraparound flaw within the image processing component of the Orthanc server. Specifically, when the server processes specially crafted PNG or JPEG image files, an integer overflow in a pitch and buffer-size computation can occur. This faulty calculation leads to an out-of-bounds write operation on the heap memory.

Successful exploitation of this flaw allows an authenticated remote attacker to trigger a denial-of-service (DoS) condition. By submitting a malicious image file, the attacker can cause the Orthanc process to crash, rendering the DICOM server unavailable. This could disrupt critical healthcare workflows that rely on the availability of medical imaging data.

The CVSS v3.1 base score for this vulnerability is 8.1 HIGH, with a CVSS v4.0 score of 7.2 HIGH. The attack vector is network-based, requires low complexity, and necessitates only low privileges to exploit. The potential impact includes significant data integrity issues and availability loss.

The vendor, Orthanc, has addressed this vulnerability by releasing version 1.13.0 of the DICOM Server. CISA strongly recommends that all users update to this patched version immediately to mitigate the risk of exploitation. The advisory also provides a link to the vendor's download page for the updated software.

CISA emphasizes that no known public exploitation of this specific vulnerability has been reported at this time. However, given the critical nature of healthcare infrastructure and the potential for disruption, proactive patching is essential. The agency also reiterates its general cybersecurity recommendations for control systems, including minimizing network exposure, implementing firewalls, and using secure remote access methods like VPNs.

This advisory serves as a reminder of the ongoing security challenges within the healthcare sector, where medical devices and software often handle sensitive patient data. Vulnerabilities in systems like Orthanc DICOM Server can have far-reaching consequences, impacting patient care and data privacy. Organizations are urged to conduct thorough impact and risk assessments before deploying any defensive measures.

Synthesized by Vypr AI