AI analysis
CVE-2026-87020 is an integer overflow (CWE-190) in the pitch and buffer-size computation used when Orthanc DICOM Server decodes PNG images, which causes a heap out-of-bounds write. It is triggered when the server decodes an attacker-supplied PNG; the CVSS 4.0 vector (AV:N/AC:L/PR:L/UI:N) indicates the attacker needs network access and some level of authenticated privileges, with no user interaction required. A successful out-of-bounds write corrupts heap memory, which per the scoring has high integrity and availability impact (service crashes and data corruption); arbitrary code execution has not been demonstrated publicly. Affected parties are operators of Orthanc DICOM servers, which are commonly used for medical imaging in hospitals, clinics, and research environments; the data does not specify affected or fixed version ranges. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: No fixed version number was provided in the data; monitor the Orthanc project's official security advisory and upgrade to the patched release as soon as it is published. In the meantime, restrict Orthanc's REST/HTTP (default 8042) and DICOM (default 4242) services to trusted, authenticated users and internal networks, review which clients can submit image data for decoding, and investigate any unexplained service crashes.
Affected
| Orthanc (open-source project; assigned by CISA ICS-CERT) Orthanc DICOM Server | — |
Estimated exposure
moderate≈10k–100k installations worldwide (estimate; mostly internal hospital/research deployments, with only a subset internet-exposed) — Orthanc is a widely adopted open-source DICOM/PACS server in healthcare and research, typically deployed on internal networks rather than directly internet-facing, which plausibly puts the installed base in the tens of thousands; no public…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.