CVE-2026-52868Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-30); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-01: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-01: 106-3007-01
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-302
Disclosure2
2026-07-011
Disclosure1
Full discourse3 posts
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-52868 OFFIS DCMTK Path traversal could let unauthenticated attackers read medical worklist records outside intended storage areas Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-06-30/TIER_2_CVE-2026-52868.md #CyberSecurity #HealthcareCybersecurity #VulnerabilityManagement

    Post summary

    The post announces CVE-2026-52868, a path traversal flaw in OFFIS DCMTK that permits unauthenticated reading of medical worklist records from outside the intended directories.

    0001041
    56 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-52868 Unauthenticated Directory Traversal Enabling Cross-Departmental Worklist Record Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-52868

    Post summary

    A new CVE-2026-52868 is disclosed as an unauthenticated directory traversal that could allow cross‑departmental access to worklist records.

    00010104
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-52868 An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross d… https://www.cve.org/CVERecord?id=CVE-2026-52868

    Post summary

    CVE‑2026‑52868 discloses an unauthorized read of worklist records across directory boundaries in multi‑area deployments; no PoC, exploit, or patch is mentioned.

    00000639
    57.7K followersView on X

Explore more