Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the applications HTTP Basic Authentication implementation.
Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.