Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Multiple DCM4CHE Vulnerabilities Enable Deletion, Forgery, and DoS in Medical Imaging Archives

Four security bugs in the open‑source DCM4CHE toolkit can delete patient scans, inject forged studies, or cause denial‑of‑service. Healthcare organizations that rely on DCM4CHE‑based PACS must address the flaws to maintain data integrity and audit readiness.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 databreachtoday.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
5 recommended
📰
Source
databreachtoday.com

Multiple DCM4CHE Vulnerabilities Enable Deletion, Forgery, and DoS in Medical Imaging Archives

What It Is – An independent researcher disclosed four publicly‑reported bugs in the open‑source DCM4CHE toolkit (used to build DICOM/PACS archives). The flaws allow mass deletion of stored scans, unauthenticated injection or reassignment of studies, and denial‑of‑service via infinite‑loop parsers.

Exploitability – No public evidence of exploitation in a production healthcare environment; proof‑of‑concept code and GitHub Security Advisories are available. CVSS scores are pending.

Affected Products – DCM4CHE (all versions referenced in the advisories) and any commercial or custom PACS solutions that embed the toolkit.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous third‑party risk monitoring; an open‑source component can introduce data‑integrity and availability gaps that affect patient safety.
  • Provides concrete evidence that control objectives around vendor oversight, secure configuration, and audit logging must be demonstrable to regulators and auditors.
  • Highlights the importance of maintaining up‑to‑date evidence of remediation (patches, configuration baselines) to support a defensible audit trail.

Recommended Actions –

  • Apply the patches released in the GitHub Security Advisories immediately.
  • Inventory all deployments that include DCM4CHE and map them to your third‑party risk register.
  • Enforce network‑level segmentation and strict DICOM/HL7 authentication to limit unauthenticated access.
  • Enable detailed logging of archive operations and retain logs for forensic review.
  • Conduct a rapid control‑mapping exercise to verify that vendor‑risk and data‑integrity controls meet your framework of record.

Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/medical-imaging-archive-flaws-put-patient-scans-at-risk-a-32908 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →