CVE-2026-47662: Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLs
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR surface allows an authenticated caller with only coarse operation authorities to act on attacker-chosen resource families because those entrypoints do not consistently enforce the documented per-resource read and write authorities. The documented authorization model requires an operation authority (e.g. pathling:search) to be paired with the matching per-resource read or write authority (e.g. pathling:read:Patient). Delete and batch are documented to require write authority for all referenced resource types. However, typed search, update, and related handlers are annotated only with @OperationAccess(...) and act on the provider-selected resource type without checking the corresponding per-resource authority. This is fixed in Pathling Server 2.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pathling Serverto a version that resolves this vulnerability.Fixed in 2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47662?
CVE-2026-47662 has a risk rating of 55.
How do I fix CVE-2026-47662?
To remediate CVE-2026-47662, upgrade to Pathling Server version 2.0.0 or later.
What is the impact of CVE-2026-47662?
CVE-2026-47662 allows for bearer-token exfiltration and persistent warehouse poisoning through unvalidated manifest output URLs.
Who is affected by CVE-2026-47662?
CVE-2026-47662 affects users of Pathling Server versions prior to 2.0.0.
What types of vulnerabilities are associated with CVE-2026-47662?
CVE-2026-47662 is associated with input validation issues and server-side request forgery (SSRF) vulnerabilities.