PT-2026-69140 · Unknown · Pathling Server

CVE-2026-47663

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Pathling Server versions prior to 2.0.0
Description Pathling Server contains an authorization bypass in its typed CRUD, search, and batch FHIR surface. Authenticated users with coarse operation authorities can interact with resource families chosen by an attacker because certain entrypoints fail to consistently enforce per-resource read and write authorities. While the authorization model requires operation authorities (such as pathling:search) to be paired with specific per-resource authorities (such as pathling:read:Patient), typed search, update, and related handlers use the @OperationAccess(...) annotation and process the provider-selected resource type without verifying the required per-resource authority.
Recommendations Update to version 2.0.0.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47663
GHSA-Q62Q-2M46-R7RV

Affected Products

Pathling Server