What is CVE-2026-62293?
This vulnerability in HAPI FHIR allows an unauthenticated attacker to inject malicious content into scan.html via the Scanner.java component by manipulating Implementation Guide titles, profile titles, or source references. The issue affects healthcare interoperability implementations and arises from improper escaping of attacker-controlled data. Organizations should immediately update to version 6.9.11 or later to remediate the risk.
Azərbaycanca: Bu zəiflik HAPI FHIR kitabxanasında aşkarlanıb və təsdiqlənməmiş istifadəçiyə Scanner.java faylı vasitəsilə scan.html-ə Injection həyata keçirməyə imkan verir. Əsasən səhiyyə sistemlərində istifadə olunan bu boşluq, təcavüzkarın Implementation Guide başlıqları kimi idarə etdiyi dəyərləri təhlükəsiz işlətməməsi səbəbindən yaranır. Təsirlənmiş versiyaları işlədən təşkilatlar dərhal 6.9.11 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Through which component of the HAPI FHIR library is CVE-2026-62293 exploited?
This vulnerability is exploited through the Scanner.java component, allowing injection into the scan.html file.
To mitigate CVE-2026-62293, what version should be updated to?
To remediate this risk, organizations should immediately update to version 6.9.11 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.