CVE-2026-47663: CWE-285: Improper Authorization in aehrc pathling
CVE-2026-47663 is a high-severity improper authorization vulnerability in Pathling Server prior to version 2.0.0. The issue arises because typed CRUD/search/batch FHIR operations do not consistently enforce per-resource read and write authorities, allowing authenticated users with only coarse operation permissions to act on resource families without proper authorization. This flaw violates the documented authorization model that requires pairing operation authority with matching per-resource read or write authority. The vulnerability is fixed in Pathling Server 2.0.0.
AI Analysis
Technical Summary
Pathling Server versions before 2.0.0 have an improper authorization vulnerability (CWE-285) in their typed FHIR CRUD/search/batch interfaces. Authenticated callers with broad operation-level permissions (e.g., pathling:search) can perform actions on resource types without the required per-resource read or write authorities (e.g., pathling:read:Patient). While delete and batch operations require write authority for all referenced resource types, typed search, update, and related handlers only check operation-level access and do not enforce per-resource authorization. This inconsistency allows unauthorized access to attacker-chosen resource families. The issue is resolved in Pathling Server 2.0.0.
Potential Impact
An attacker with authenticated access and coarse operation-level permissions can perform unauthorized actions on resource families they should not have access to, potentially exposing or modifying sensitive health data. This violates the intended fine-grained authorization model and could lead to unauthorized data access or modification within health data analytics environments using Pathling Server prior to 2.0.0.
Mitigation Recommendations
Upgrade to Pathling Server version 2.0.0 or later, where this improper authorization issue is fixed. No other mitigation or workaround is documented. Patch status is not explicitly stated, but the fix is included in version 2.0.0.
CVE-2026-47663: CWE-285: Improper Authorization in aehrc pathling
Description
CVE-2026-47663 is a high-severity improper authorization vulnerability in Pathling Server prior to version 2.0.0. The issue arises because typed CRUD/search/batch FHIR operations do not consistently enforce per-resource read and write authorities, allowing authenticated users with only coarse operation permissions to act on resource families without proper authorization. This flaw violates the documented authorization model that requires pairing operation authority with matching per-resource read or write authority. The vulnerability is fixed in Pathling Server 2.0.0.
CVSS v4.0
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Pathling Server versions before 2.0.0 have an improper authorization vulnerability (CWE-285) in their typed FHIR CRUD/search/batch interfaces. Authenticated callers with broad operation-level permissions (e.g., pathling:search) can perform actions on resource types without the required per-resource read or write authorities (e.g., pathling:read:Patient). While delete and batch operations require write authority for all referenced resource types, typed search, update, and related handlers only check operation-level access and do not enforce per-resource authorization. This inconsistency allows unauthorized access to attacker-chosen resource families. The issue is resolved in Pathling Server 2.0.0.
Potential Impact
An attacker with authenticated access and coarse operation-level permissions can perform unauthorized actions on resource families they should not have access to, potentially exposing or modifying sensitive health data. This violates the intended fine-grained authorization model and could lead to unauthorized data access or modification within health data analytics environments using Pathling Server prior to 2.0.0.
Mitigation Recommendations
Upgrade to Pathling Server version 2.0.0 or later, where this improper authorization issue is fixed. No other mitigation or workaround is documented. Patch status is not explicitly stated, but the fix is included in version 2.0.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T21:10:38.797Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a76468dbf8831d53924fd8b
Added to database: 08/07/2026, 20:56:45 UTC
Last enriched: 08/07/2026, 21:11:30 UTC
Last updated: 08/07/2026, 21:11:30 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.