CVE-2026-47660

AEHRC · Pathling

Pathling versions prior to 2.0.0 are vulnerable to insufficiently protected credentials and server-side request forgery, allowing potential unauthorized access.

Executive summary

Pathling versions before 2.0.0 contain critical security flaws involving credential handling and request forgery that expose the system to unauthorized data access.

Vulnerability

This vulnerability involves CWE-522 (Insufficiently Protected Credentials) and CWE-918 (Server-Side Request Forgery). The flaws allow an unauthenticated remote attacker to manipulate server requests and potentially access protected credentials.

Business impact

The CVSS score of 8.7 reflects a high-severity risk due to the potential for unauthenticated access to sensitive clinical or health-related data. A successful exploit could lead to significant data breaches, regulatory non-compliance, and loss of trust in health analytics infrastructure.

Remediation

Immediate Action: Upgrade all instances of Pathling to version 2.0.0 or later as specified in the official vendor advisory.

Proactive Monitoring: Review server logs for suspicious outbound requests to internal or external endpoints and monitor for anomalous access patterns.

Compensating Controls: Implement strict network egress filtering to prevent the application from making unauthorized requests to internal resources.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of the vulnerabilities, immediate patching is required to secure the environment. Ensure that all deployments of Pathling are updated to version 2.0.0 to remediate these security gaps and prevent potential unauthorized access to clinical data.