Authorization Flaw in Pathling Server Enhances Risk for Health Data Analytics
CVE-2026-47662

8.7HIGH

Key Information:

Vendor

Aehrc

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-47662?

Pathling Server, a tool for implementing FHIR and clinical terminology within health data analytics, has a vulnerability prior to version 2.0.0. This flaw allows authenticated users with basic operation authorities to manipulate specific resource families without proper enforcement of the documented read and write permissions. The security model requires a pairing of operation authority with specific resource permissions. However, due to inconsistent checks, actions taken by users with merely coarse authorities can affect crash operations on potentially sensitive data. This issue has been addressed in Pathling Server version 2.0.0, enhancing the security posture of the tool.

Affected Version(s)

pathling < 2.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.