CVE-2025-15581

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-02-18 23:16

Updated : 2026-02-28 18:16


NVD link : CVE-2025-15581

Mitre link : CVE-2025-15581

CVE.ORG link : CVE-2025-15581


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication