CVE-2026-52868
OFFIS DICOM DCMTK Toolkit
An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.
- CVSS
- 8.8
- EPSS
- 0.41% 33.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.01