CVE-2026-47660
AEHRC · Pathling
Pathling versions prior to 2.0.0 are vulnerable to insufficiently protected credentials and server-side request forgery, allowing potential unauthorized access.
Executive summary
Pathling versions before 2.0.0 contain critical security flaws involving credential handling and request forgery that expose the system to unauthorized data access.
Vulnerability
This vulnerability involves CWE-522 (Insufficiently Protected Credentials) and CWE-918 (Server-Side Request Forgery). The flaws allow an unauthenticated remote attacker to manipulate server requests and potentially access protected credentials.
Business impact
The CVSS score of 8.7 reflects a high-severity risk due to the potential for unauthenticated access to sensitive clinical or health-related data. A successful exploit could lead to significant data breaches, regulatory non-compliance, and loss of trust in health analytics infrastructure.
Remediation
Immediate Action: Upgrade all instances of Pathling to version 2.0.0 or later as specified in the official vendor advisory.
Proactive Monitoring: Review server logs for suspicious outbound requests to internal or external endpoints and monitor for anomalous access patterns.
Compensating Controls: Implement strict network egress filtering to prevent the application from making unauthorized requests to internal resources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the nature of the vulnerabilities, immediate patching is required to secure the environment. Ensure that all deployments of Pathling are updated to version 2.0.0 to remediate these security gaps and prevent potential unauthorized access to clinical data.