CVE-2026-5663: OFFIS DCMTK storescp storescp.cc executeOnEndOfStudy os command injection
A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The patch is named edbb085e45788dccaf0e64d71534cfca925784b8. Applying a patch is the recommended action to fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5663?
CVE-2026-5663 is classified as a critical vulnerability due to its potential for command injection.
How do I fix CVE-2026-5663?
To remediate CVE-2026-5663, upgrade OFFIS DCMTK to version 3.7.1 or later.
What components are affected by CVE-2026-5663?
CVE-2026-5663 affects the storescp application within the OFFIS DCMTK up to version 3.7.0.
What is the impact of CVE-2026-5663?
Exploitation of CVE-2026-5663 can allow an attacker to execute arbitrary commands on the system.
Who is the vendor for CVE-2026-5663?
The vendor for CVE-2026-5663 is OFFIS, responsible for the DCMTK software.