PatchSiren cyber security CVE debrief
CVE-2026-44628 OFFIS DICOM CVE debrief
The OFFIS DCMTK Toolkit is affected by a vulnerability that allows an unauthenticated attacker to crash the worklist server with a single crafted query. The vulnerability exists when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record. This issue is related to the unauthenticated query functionality. Organizations utilizing OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts, should prioritize patching to prevent potential crashes of the worklist server. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Furthermore, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Vendor
- OFFIS DICOM
- Product
- DCMTK
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-30
- Original CVE updated
- 2026-06-30
- Advisory published
- 2026-06-30
- Advisory updated
- 2026-06-30
Who should care
Organizations utilizing OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts, should prioritize patching to prevent potential crashes of the worklist server. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Finally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Affected operators, platforms, and security teams should be aware of the vulnerability and take necessary actions to mitigate it. They should also review the vulnerability management process and asset inventory to ensure that all affected systems are identified and prioritized for patching. Furthermore, they should consider implementing additional security controls, such as monitoring and detection, to reduce the risk of exploitation. By taking these steps, organizations can reduce the risk of exploitation and minimize the impact of a potential attack. The vulnerability management process should be reviewed to ensure that all affected systems are identified and prioritized for patching. Asset inventory should also be reviewed to ensure that all affected systems are accounted for. Security teams should be aware of the vulnerability and take necessary actions to mitigate it. They should also review the vulnerability management process and asset inventory to ensure that all affected systems are identified and prioritized for patching. Additionally, they should consider implementing additional security controls, such as monitoring and detection, to reduce the risk of exploitation. By taking these steps, organizations can reduce the risk of exploitation and minimize the impact of a potential attack. The affected product or component is OFFIS DCMTK Toolkit. The vulnerability class is related to unaut
Technical summary
An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record. This can be done by reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. The vulnerability affects OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts.
Defensive priority
Organizations using OFFIS DCMTK Toolkit should prioritize patching to prevent potential crashes of the worklist server.
Recommended defensive actions
- Apply the latest fix from the GitHub release once it becomes available.
- Download and implement the latest GitHub release.
- Verify the Called AE Title / storage directory and lockfile configurations.
- Monitor worklist server logs for potential crafted queries.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The source item from CISA CSAF provides details on the vulnerability, including the description and affected products. However, further information is limited, and additional verification is recommended. Organizations should verify the Called AE Title / storage directory and lockfile configurations. They should also monitor worklist server logs for potential crafted queries and review compensating controls for exposed systems while remediation is scheduled and verified.
Official resources
-
CVE-2026-44628 CVE record
CVE.org
-
CVE-2026-44628 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T06:00:00.000Z and has not been modified since then.