Pathling Server's `$import-pnp` operation allows a caller-supplied `exportUrl` to be used as a remote FHIR Bulk Export endpoint without constraining it to a trusted source. This issue, fixed in Pathling Server 2.0.0, enables an attacker to bypass the `allowableSources` allowlist that protects the ordinary `$import` operation. As a workaround, disable the `$import-pnp` operation or do not configure PNP credentials.
CVE-2026-47663 is a high-severity vulnerability in Pathling Server, a tool for using FHIR and clinical terminology in health data analytics. An authenticated caller with coarse operation authorities can perform unauthorized actions on attacker-chosen resource families due to inconsistent enforcement of per-resource read and write authorities. This issue is fixed in Pathling Server 2.0.0.
CVE-2026-47662 is a high-severity vulnerability in Pathling Server, a tool for using FHIR and clinical terminology in health data analytics. An authenticated caller with coarse operation authorities can perform unauthorized actions on attacker-chosen resource families due to inconsistent enforcement of per-resource read and write authorities. This issue is fixed in Pathling Server version 2.0.0.
CVE-2026-47661 is a high-severity vulnerability in Pathling Server, a tool for health data analytics. An attacker can exploit this vulnerability to read files from the warehouse database by manipulating the `file` parameter in the `/$result` endpoint. This issue is fixed in Pathling Server version 2.0.0. As an interim mitigation, users can disable async export operations or enable authentication to restri [truncated]
Pathling Server's bulk-submit operation allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that isn't validated against `pathling.bulkSubmit.allowableSources`. This issue, fixed in Pathling Server 2.0.0, could lead to security risks if exploited. Health data analytics organizations should verify their exposure and take necessary actions to mitigate the vulnerability. The vulner [truncated]
CVE-2026-47659 is a high-severity vulnerability in Pathling Server, a tool for health data analytics. An attacker can exploit this vulnerability to read files outside the intended directory by manipulating the `file` parameter in the `/$result` endpoint. This issue is fixed in Pathling Server version 2.0.0. The vulnerability allows an attacker to access files outside the intended directory due to insuffic [truncated]