CVE-2026-52868: OFFIS DCMTK Toolkit Path Traversal
Published Jun 30, 2026
·Updated
An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.
Affected Software
1 affected component
OFFIS DCMTK Toolkit
Event History
Jun 30, 2026
CVE Published
via MITRE·09:06 PM
Data Sourced
via MITRE·09:06 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-52868?
CVE-2026-52868 has a high severity score of 8.2.
2
How do I fix CVE-2026-52868?
To address CVE-2026-52868, ensure that access controls are properly implemented to restrict directory traversal.
3
What kind of attack is facilitated by CVE-2026-52868?
CVE-2026-52868 allows unauthenticated attackers to exploit path traversal vulnerabilities to read unauthorized worklist records.
4
What software is affected by CVE-2026-52868?
The CVE-2026-52868 vulnerability affects the OFFIS DCMTK Toolkit.
5
What impact does CVE-2026-52868 have on data security?
CVE-2026-52868 can potentially compromise data separation across departments or clinics, leading to unauthorized access to sensitive information.