Description

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

INFO

Published Date :

2026-02-18T22:59:55.491Z

Last Modified :

2026-02-28T18:05:15.456Z

Source :

PRJBLK
AFFECTED PRODUCTS

The following products are affected by CVE-2025-15581 vulnerability.

Vendors Products
Orthanc-server
  • Orthanc

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability