Pathling Server Vulnerability in FHIR Integration Tools by Aehrc
CVE-2026-47664

8.6HIGH

Key Information:

Vendor

Aehrc

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-47664?

The Pathling Server, a toolset designed for seamless integration with FHIR and clinical terminology in health data analytics, has a vulnerability in its $import-pnp operation. This flaw allows an attacker to supply an exportUrl that could point to an untrusted remote FHIR Bulk Export endpoint without adequate validation. As a result, the server can create a bulk-export client based on user-provided credentials and download files from any specified host, effectively bypassing the established allowableSources allowlist designed to ensure secure file imports. The latest version, 2.0.0, addresses this vulnerability. Users are advised to either update to this version or disable the $import-pnp operation to mitigate potential risks.

Affected Version(s)

pathling < 2.0.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.