PatchSiren

aehrc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH aehrc CVE published 2026-08-07

CVE-2026-47664

Pathling Server's `$import-pnp` operation allows a caller-supplied `exportUrl` to be used as a remote FHIR Bulk Export endpoint without constraining it to a trusted source. This issue, fixed in Pathling Server 2.0.0, enables an attacker to bypass the `allowableSources` allowlist that protects the ordinary `$import` operation. As a workaround, disable the `$import-pnp` operation or do not configure PNP credentials.

HIGH aehrc CVE published 2026-08-07

CVE-2026-47663

CVE-2026-47663 is a high-severity vulnerability in Pathling Server, a tool for using FHIR and clinical terminology in health data analytics. An authenticated caller with coarse operation authorities can perform unauthorized actions on attacker-chosen resource families due to inconsistent enforcement of per-resource read and write authorities. This issue is fixed in Pathling Server 2.0.0.

HIGH aehrc CVE published 2026-08-07

CVE-2026-47662

CVE-2026-47662 is a high-severity vulnerability in Pathling Server, a tool for using FHIR and clinical terminology in health data analytics. An authenticated caller with coarse operation authorities can perform unauthorized actions on attacker-chosen resource families due to inconsistent enforcement of per-resource read and write authorities. This issue is fixed in Pathling Server version 2.0.0.

HIGH aehrc CVE published 2026-08-07

CVE-2026-47661

CVE-2026-47661 is a high-severity vulnerability in Pathling Server, a tool for health data analytics. An attacker can exploit this vulnerability to read files from the warehouse database by manipulating the `file` parameter in the `/$result` endpoint. This issue is fixed in Pathling Server version 2.0.0. As an interim mitigation, users can disable async export operations or enable authentication to restri [truncated]

HIGH aehrc CVE published 2026-08-07

CVE-2026-47660

Pathling Server's bulk-submit operation allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that isn't validated against `pathling.bulkSubmit.allowableSources`. This issue, fixed in Pathling Server 2.0.0, could lead to security risks if exploited. Health data analytics organizations should verify their exposure and take necessary actions to mitigate the vulnerability. The vulner [truncated]

HIGH aehrc CVE published 2026-08-07

CVE-2026-47659

CVE-2026-47659 is a high-severity vulnerability in Pathling Server, a tool for health data analytics. An attacker can exploit this vulnerability to read files outside the intended directory by manipulating the `file` parameter in the `/$result` endpoint. This issue is fixed in Pathling Server version 2.0.0. The vulnerability allows an attacker to access files outside the intended directory due to insuffic [truncated]