What is CVE-2026-47663?
In Pathling Server versions prior to 2.0.0, an authenticated user with coarse operation authorities can act on attacker-chosen resources via the typed CRUD/search/batch FHIR surface. This may lead to unauthorized data manipulation. Upgrading to version 2.0.0 or later is recommended.
Azərbaycanca: Pathling Server-in 2.0.0-dən əvvəlki versiyalarında autentifikasiyalı istifadəçi, CRUD/search/batch FHIR əməliyyatları üzərində kifayət qədər icazə məhdudiyyəti olmadan, təcavüzkarın seçdiyi resurslar üzərində əməliyyatlar apara bilir. Bu, icazəsiz məlumat manipulyasiyasına səbəb ola bilər. Pathling Server-in 2.0.0 və ya daha yuxarı versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Through which operations can CVE-2026-47663 be exploited in Pathling Server?
The vulnerability can be exploited via typed CRUD/search/batch FHIR operations due to insufficient permission restrictions.
How can CVE-2026-47663 be mitigated?
Upgrading Pathling Server to version 2.0.0 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.