CVE-2026-50003: OFFIS DCMTK Toolkit Path Traversal
Published Jun 30, 2026
·Updated
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
Affected Software
1 affected component
OFFIS DCMTK Toolkit
Event History
Jun 30, 2026
CVE Published
via MITRE·09:27 PM
Data Sourced
via MITRE·09:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-50003?
CVE-2026-50003 has a critical severity score of 9.8.
2
What type of vulnerability is CVE-2026-50003?
CVE-2026-50003 is a path traversal vulnerability found in the OFFIS DCMTK Toolkit.
3
How does CVE-2026-50003 exploit the DCMTK client?
CVE-2026-50003 allows a malicious server to direct the DCMTK client to write files outside the intended output directory.
4
What impact does CVE-2026-50003 have on data security?
CVE-2026-50003 can lead to unauthorized access and potential exposure of sensitive data.
5
How can I mitigate CVE-2026-50003?
To mitigate CVE-2026-50003, ensure that your version of OFFIS DCMTK Toolkit is updated to the latest patched release.