PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44628 OFFIS DICOM CVE debrief

The OFFIS DCMTK Toolkit is affected by a vulnerability that allows an unauthenticated attacker to crash the worklist server with a single crafted query. The vulnerability exists when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record. This issue is related to the unauthenticated query functionality. Organizations utilizing OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts, should prioritize patching to prevent potential crashes of the worklist server. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Furthermore, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented.

Vendor
OFFIS DICOM
Product
DCMTK
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-06-30
Advisory published
2026-06-30
Advisory updated
2026-06-30

Who should care

Organizations utilizing OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts, should prioritize patching to prevent potential crashes of the worklist server. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Finally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Affected operators, platforms, and security teams should be aware of the vulnerability and take necessary actions to mitigate it. They should also review the vulnerability management process and asset inventory to ensure that all affected systems are identified and prioritized for patching. Furthermore, they should consider implementing additional security controls, such as monitoring and detection, to reduce the risk of exploitation. By taking these steps, organizations can reduce the risk of exploitation and minimize the impact of a potential attack. The vulnerability management process should be reviewed to ensure that all affected systems are identified and prioritized for patching. Asset inventory should also be reviewed to ensure that all affected systems are accounted for. Security teams should be aware of the vulnerability and take necessary actions to mitigate it. They should also review the vulnerability management process and asset inventory to ensure that all affected systems are identified and prioritized for patching. Additionally, they should consider implementing additional security controls, such as monitoring and detection, to reduce the risk of exploitation. By taking these steps, organizations can reduce the risk of exploitation and minimize the impact of a potential attack. The affected product or component is OFFIS DCMTK Toolkit. The vulnerability class is related to unaut

Technical summary

An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record. This can be done by reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. The vulnerability affects OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts.

Defensive priority

Organizations using OFFIS DCMTK Toolkit should prioritize patching to prevent potential crashes of the worklist server.

Recommended defensive actions

  • Apply the latest fix from the GitHub release once it becomes available.
  • Download and implement the latest GitHub release.
  • Verify the Called AE Title / storage directory and lockfile configurations.
  • Monitor worklist server logs for potential crafted queries.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The source item from CISA CSAF provides details on the vulnerability, including the description and affected products. However, further information is limited, and additional verification is recommended. Organizations should verify the Called AE Title / storage directory and lockfile configurations. They should also monitor worklist server logs for potential crafted queries and review compensating controls for exposed systems while remediation is scheduled and verified.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44628 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44628

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44628 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44628

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-181-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-181-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.