Authentication Bypass Vulnerability in Orthanc Server by Orthanc
CVE-2025-0896
9.2CRITICAL
What is CVE-2025-0896?
The Orthanc server prior to version 1.5.8 is susceptible to a significant security flaw that allows remote access without basic authentication being enabled by default. This lack of authentication can lead to unauthorized access, enabling attackers to exploit the system, potentially compromising sensitive data and functionalities within the server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Orthanc server 0 < 1.5.8
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Amitay Dan reported this vulnerability to Orthanc
Souvik Kandar reported this vulnerability to CISA
