CVE-2026-12473
Received Received - Intake
Unauthenticated OIDC Token Leak in OHIF DICOMWebProxy

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: ICS-CERT

Description
Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

The vulnerability can lead to unauthorized disclosure of the authenticated user's OIDC Bearer token to an attacker-controlled server. This could allow attackers to impersonate the user or gain unauthorized access to protected resources, leading to potential data breaches or unauthorized actions within the affected system.

Executive Summary

This vulnerability involves two data sources, DICOMWebProxy and DICOMJSON, which in their default configuration fetch an arbitrary URL parameter without validating it. Because of this, a global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into these requests. As a result, the token can be sent to an attacker-controlled server, potentially exposing sensitive authentication credentials.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12473. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart