Impact
The vulnerability in Pathling Server allows an authenticated caller with broad operation authorities to act on arbitrary FHIR resource families because the API endpoints do not enforce per-resource read or write permissions. An attacker can use these endpoints to exfiltrate bearer tokens and poison the warehouse by providing unvalidated manifest output URLs, thereby compromising data integrity and exposing protected health information.
Affected Systems
Pathling Server is impacted; all releases prior to version 2.0.0 of Pathling Server have this flaw.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The attack requires only authentication with coarse operation authorities and can be carried out via normal API calls, making exploitation straightforward for insiders or compromised accounts. The flaw is not listed in the CISA KEV catalog and the EPSS score is not available, but the high CVSS and lack of additional mitigations suggest a significant risk of exploitation in environments where Pathling is exposed to internal or external users.
OpenCVE Enrichment