PatchSiren cyber security CVE debrief
CVE-2026-47660 aehrc CVE debrief
Pathling Server's bulk-submit operation allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that isn't validated against `pathling.bulkSubmit.allowableSources`. This issue, fixed in Pathling Server 2.0.0, could lead to security risks if exploited. Health data analytics organizations should verify their exposure and take necessary actions to mitigate the vulnerability. The vulnerability allows an attacker to potentially manipulate the OAuth flow, leading to unauthorized access or other security breaches. Organizations should assess their current version of Pathling Server and upgrade to version 2.0.0 or apply compensating controls to restrict the `oauthMet
- Vendor
- aehrc
- Product
- pathling
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-07
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-07
- Advisory updated
- 2026-09-09
Who should care
Health data analytics organizations using Pathling Server should assess their exposure and take necessary actions to mitigate the vulnerability. These organizations should verify their current version of Pathling Server and upgrade to version 2.0.0 or apply compensating controls to restrict the `oauthMetadataUrl` parameter. Additionally, security teams and vulnerability management teams should review their current security configurations and implement to
Why it matters
Health data analytics organizations using Pathling Server should assess their exposure and take necessary actions to mitigate the vulnerability. The issue allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that is not validated, potentially leading to security risks. Defenders should verify their exposure, upgrade to version 2.0.0 or apply compensating controls, and monitor for potential security incidents.
- Verify exposure by checking current Pathling Server version
- Upgrade to Pathling Server 2.0.0 or later
- Apply compensating controls to restrict `oauthMetadataUrl` parameter
Technical summary
The Pathling Server bulk-submit operation allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that isn't validated against `pathling.bulkSubmit.allowableSources`. This issue, fixed in Pathling Server 2.0.0, could lead to security risks if exploited. The vulnerability is related to the handling of OAuth metadata URLs in the bulk-submit operation. An attacker could potentially manipulate the OAuth flow, leading to unauthorized access or other security breaches. The issue is addressed by validating the `oauthMetadataUrl` parameter against a list of allowable sources.
Defensive priority
Health data analytics organizations using Pathling Server should verify their exposure and upgrade to version 2.0.0 or apply compensating controls.
Recommended defensive actions
- Verify exposure by checking current Pathling Server version
- Upgrade to Pathling Server 2.0.0 or later
- Apply compensating controls to restrict `oauthMetadataUrl` parameter
- Review and update security configurations to prevent similar vulnerabilities
- Monitor for potential security incidents related to this vulnerability
- Conduct regular security audits to identify and address potential risks
- Implement additional security measures to protect against unauthorized access
Evidence notes
The CVE record and NVD entry provide details on the Pathling Server vulnerability. The issue allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that is not validated, potentially leading to security risks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47660 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47660
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47660 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47660
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/aehrc/pathling/security/advisories/GHSA-245h-c573-9vr5
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.