Path Traversal Vulnerability in Pathling Server Affects Health Data Analytics
CVE-2026-47661

8.7HIGH

Key Information:

Vendor

Aehrc

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-47661?

Pathling, a suite of tools for FHIR and clinical terminology within health data analytics, exhibits a vulnerability in its /$result endpoint prior to version 2.0.0. The endpoint permits attackers to exploit path traversal sequences in the file parameter when a valid async export job ID is supplied. The handler inadequately verifies and normalizes the requested file path, posing a risk of unauthorized access to other files in the warehouse database. This exposure is particularly critical as the async export scratch space shares the same root with persisted resource tables, allowing attackers to leverage their own export jobs to read sensitive files. The vulnerability has been addressed in Pathling Server 2.0.0, and users are advised to disable async export operations or enforce strict authentication to mitigate potential exploits.

Affected Version(s)

pathling < 2.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.