PT-2026-69140 · Unknown · Pathling Server
CVE-2026-47663
·
Published
2026-08-07
·
Updated
2026-08-07
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Pathling Server versions prior to 2.0.0
Description
Pathling Server contains an authorization bypass in its typed CRUD, search, and batch FHIR surface. Authenticated users with coarse operation authorities can interact with resource families chosen by an attacker because certain entrypoints fail to consistently enforce per-resource
read and write authorities. While the authorization model requires operation authorities (such as pathling:search) to be paired with specific per-resource authorities (such as pathling:read:Patient), typed search, update, and related handlers use the @OperationAccess(...) annotation and process the provider-selected resource type without verifying the required per-resource authority.Recommendations
Update to version 2.0.0.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pathling Server