What is CVE-2026-47664?
In Pathling Server before version 2.0.0, the `$import-pnp` operation does not properly validate a caller-supplied `exportUrl`, potentially allowing an unauthenticated attacker to achieve remote code execution by specifying a malicious FHIR Bulk Export endpoint. Affected systems are strongly advised to upgrade to version 2.0.0 immediately.
Azərbaycanca: Pathling Server-in 2.0.0 versiyasından əvvəl `$import-pnp` əməliyyatı istifadəçi tərəfindən təqdim edilən `exportUrl` parametrini düzgün yoxlamadığı üçün uzaqdan kod icrası zəifliyi mövcuddur. Bu, təsdiqlənməmiş hücumçuya zərərli FHIR Bulk Export endpoint vasitəsilə sistemə müdaxilə etməyə imkan verə bilər. Təsirə məruz qalan sistemlərin dərhal 2.0.0 versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Pathling Server are affected by CVE-2026-47664?
All versions of Pathling Server before version 2.0.0 are affected by this vulnerability.
What can an attacker achieve by exploiting CVE-2026-47664?
An unauthenticated attacker can achieve remote code execution (RCE) by specifying a malicious FHIR Bulk Export endpoint via the `exportUrl` parameter in the `$import-pnp` operation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.