CVE-2026-47663

aehrc · pathling

An improper authorization vulnerability in Pathling allows unauthenticated attackers to access sensitive clinical data.

Executive summary

An improper authorization flaw in Pathling permits unauthenticated access to sensitive health data, creating a significant risk of data exposure.

Vulnerability

This vulnerability is an improper authorization (CWE-285) issue. It allows an unauthenticated attacker to bypass security controls and access protected FHIR or clinical terminology data.

Business impact

With a CVSS score of 8.7, this vulnerability represents a critical threat to data privacy and regulatory compliance. Exposure of clinical and health-related data can lead to severe reputational damage, legal liabilities, and the compromise of sensitive patient information.

Remediation

Immediate Action: Update Pathling to version 2.0.0 or higher immediately to resolve the authorization bypass.

Proactive Monitoring: Audit access logs for unauthorized requests to clinical endpoints and monitor for unusual spikes in data retrieval activities.

Compensating Controls: Ensure the instance is not exposed to the public internet and utilize network-level access control lists (ACLs) to restrict traffic to known, authorized internal services.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The risk of unauthorized access to clinical data necessitates an immediate update. Organizations should ensure that Pathling is not accessible from untrusted networks while the remediation process is underway.