Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
Attackers are actively exploiting the SSRF flaw CVE-2026‑12473 in OHIF DICOM viewers to steal clinician OIDC tokens and access patient data, facilitating lateral movement within healthcare networks.
ADK Cyber[verified]@ADKCyberDisclosure
The tweet discloses CVE‑2026‑12473 as a high‑severity vulnerability affecting OHIF medical imaging components and prompts healthcare organizations to review exposure on the NVD.
WindowsForum.com[verified]@windowsforumPatch
CVE-2026-12473 is a token‑leak vulnerability caused by a crafted link impacting OHIF's OIDC secrets; the issue has been fixed by patching to OHIF v3.12.2.
WindowsForum.com[verified]@windowsforumPatch
The forum post highlights that CVE-2026-12473 leads to token leaks through crafted links in the OHIF viewer, and notes that patch version 3.12.2 is available to fix the issue.
Nelson Brilhante@zumuhaDisclosure
The post announces that CVE-2026-12473 compromises the OHIF medical imaging viewer by allowing unauthorized key theft and links to a source for details on mitigation.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE-2026-12473, describing how two data sources use an unvalidated URL parameter, but it provides no PoC, exploit code, or patch information.
CVE@CVEnewGeneral
The text reports a basic flaw in two default configurations, but lacks evidence of exploitation, fixes, or deeper technical detail.