CVE Vulnerabilities

CVE-2025-15581

Improper Authentication

Published: Feb 18, 2026 | Modified: Feb 19, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the applications HTTP Basic Authentication implementation.

Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Potential Mitigations

References