PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47660 aehrc CVE debrief

Pathling Server's bulk-submit operation allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that isn't validated against `pathling.bulkSubmit.allowableSources`. This issue, fixed in Pathling Server 2.0.0, could lead to security risks if exploited. Health data analytics organizations should verify their exposure and take necessary actions to mitigate the vulnerability. The vulnerability allows an attacker to potentially manipulate the OAuth flow, leading to unauthorized access or other security breaches. Organizations should assess their current version of Pathling Server and upgrade to version 2.0.0 or apply compensating controls to restrict the `oauthMet

Vendor
aehrc
Product
pathling
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-09-09
Advisory published
2026-08-07
Advisory updated
2026-09-09

Who should care

Health data analytics organizations using Pathling Server should assess their exposure and take necessary actions to mitigate the vulnerability. These organizations should verify their current version of Pathling Server and upgrade to version 2.0.0 or apply compensating controls to restrict the `oauthMetadataUrl` parameter. Additionally, security teams and vulnerability management teams should review their current security configurations and implement to

Why it matters

Health data analytics organizations using Pathling Server should assess their exposure and take necessary actions to mitigate the vulnerability. The issue allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that is not validated, potentially leading to security risks. Defenders should verify their exposure, upgrade to version 2.0.0 or apply compensating controls, and monitor for potential security incidents.

  • Verify exposure by checking current Pathling Server version
  • Upgrade to Pathling Server 2.0.0 or later
  • Apply compensating controls to restrict `oauthMetadataUrl` parameter

Technical summary

The Pathling Server bulk-submit operation allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that isn't validated against `pathling.bulkSubmit.allowableSources`. This issue, fixed in Pathling Server 2.0.0, could lead to security risks if exploited. The vulnerability is related to the handling of OAuth metadata URLs in the bulk-submit operation. An attacker could potentially manipulate the OAuth flow, leading to unauthorized access or other security breaches. The issue is addressed by validating the `oauthMetadataUrl` parameter against a list of allowable sources.

Defensive priority

Health data analytics organizations using Pathling Server should verify their exposure and upgrade to version 2.0.0 or apply compensating controls.

Recommended defensive actions

  • Verify exposure by checking current Pathling Server version
  • Upgrade to Pathling Server 2.0.0 or later
  • Apply compensating controls to restrict `oauthMetadataUrl` parameter
  • Review and update security configurations to prevent similar vulnerabilities
  • Monitor for potential security incidents related to this vulnerability
  • Conduct regular security audits to identify and address potential risks
  • Implement additional security measures to protect against unauthorized access

Evidence notes

The CVE record and NVD entry provide details on the Pathling Server vulnerability. The issue allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that is not validated, potentially leading to security risks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47660 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47660

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47660 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47660

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.