A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-10173

CVE-2026-10173: Orthanc Explorer 2 XSS Vulnerability

CVE-2026-10173 is a cross-site scripting flaw in Orthanc Explorer 2 up to version 1.12.0 affecting the URL Handler component. Attackers can exploit this remotely via the remote-source parameter. This article covers technical details, affected versions, impact, and mitigation.

Published: June 4, 2026

CVE-2026-10173 Overview

CVE-2026-10173 is a reflected cross-site scripting (XSS) vulnerability in Orthanc Explorer 2 versions up to and including 1.12.0. The flaw resides in the URL Handler component, specifically within the WebApplication/src/components/StudyList.vue file. Attackers can manipulate the remote-source argument to inject malicious script content that executes in the context of a victim's browser session. The exploit has been published, making the vulnerability accessible to remote attackers who can lure a user into interacting with a crafted URL. A patch identified by commit 21f78ce5da668bf5233efcd1896ec7c6e3b22eae is available from the project maintainers.

Critical Impact

Remote attackers can execute arbitrary JavaScript in an authenticated user's browser session by tricking the user into clicking a malicious link targeting the remote-source URL parameter.

Affected Products

  • Orthanc Explorer 2 versions up to and including 1.12.0
  • The StudyList.vue component within the URL Handler
  • Deployments exposing Orthanc Explorer 2 over the network

Discovery Timeline

  • 2026-05-31 - CVE-2026-10173 published to NVD
  • 2026-06-01 - Last updated in NVD database

Technical Details for CVE-2026-10173

Vulnerability Analysis

The vulnerability is classified as cross-site scripting under [CWE-79]. Orthanc Explorer 2 fails to properly sanitize or encode the remote-source URL parameter before rendering it through the StudyList.vue Vue.js component. When a user navigates to a crafted URL containing attacker-controlled markup or script content, the application reflects that input back into the rendered DOM without adequate output encoding.

The attack requires user interaction, typically a click on a malicious link, which limits unsolicited mass exploitation. However, the network attack vector and lack of authentication requirements make targeted phishing scenarios viable. EPSS data indicates a probability of 0.036% with a percentile of 11.175, reflecting low observed exploit activity at this time despite the public availability of proof-of-concept code.

Root Cause

The root cause is improper neutralization of input during web page generation in the StudyList.vue component. The remote-source query parameter is consumed by the URL Handler and rendered into the page without contextual output escaping. Vue.js applications are generally safe against XSS by default, but use of unsafe rendering directives such as v-html or direct DOM manipulation with untrusted input can bypass those protections.

Attack Vector

An attacker crafts a URL pointing to the Orthanc Explorer 2 interface that includes a malicious payload in the remote-source parameter. The attacker delivers the URL through phishing, chat, or embedded links on third-party sites. When a victim with an active session clicks the link, the injected script executes in the browser, enabling actions such as session token theft, DICOM study manipulation through authenticated API calls, or pivoting to other Orthanc services.

The vulnerability manifests when the unsanitized remote-source value is passed into the rendering pipeline of StudyList.vue. Refer to the GitHub Issue Tracker and the GitHub Commit Log for the specific code changes that address this flaw.

Detection Methods for CVE-2026-10173

Indicators of Compromise

  • HTTP requests to Orthanc Explorer 2 endpoints containing remote-source parameter values with <script>, javascript:, onerror=, or encoded HTML entities
  • Outbound requests from user browsers to unfamiliar domains shortly after accessing the Orthanc Explorer 2 interface
  • Web server access logs showing unusual referrers or long URL-encoded payloads targeting Orthanc Explorer 2 routes

Detection Strategies

  • Inspect web proxy and WAF logs for query strings on Orthanc Explorer 2 URLs that contain script tags, event handlers, or base64-encoded payloads
  • Deploy Content Security Policy (CSP) violation reporting to surface attempts to load inline scripts or untrusted external resources
  • Correlate authenticated Orthanc API actions with unusual user-agent or timing patterns suggesting browser-based session abuse

Monitoring Recommendations

  • Enable verbose access logging on the reverse proxy fronting Orthanc Explorer 2 and retain query parameters for forensic review
  • Alert on Orthanc Explorer 2 versions running at or below 1.12.0 discovered through asset inventory or vulnerability scanning
  • Monitor the VulDB Vulnerability Profile and the project's GitHub repository for additional advisories or related fixes

How to Mitigate CVE-2026-10173

Immediate Actions Required

  • Upgrade Orthanc Explorer 2 to a release that incorporates commit 21f78ce5da668bf5233efcd1896ec7c6e3b22eae or later
  • Restrict access to Orthanc Explorer 2 to trusted networks using VPN or IP allowlisting until patching is complete
  • Notify users of the deployment to avoid clicking unsolicited links that point to the Orthanc Explorer 2 hostname

Patch Information

The upstream fix is published as commit 21f78ce5da668bf5233efcd1896ec7c6e3b22eae. Administrators should pull the latest release that includes this commit from the orthanc-server GitHub repository and redeploy the web application. Verify the deployed version after upgrade and clear browser caches for affected users.

Workarounds

  • Deploy a Web Application Firewall (WAF) rule that blocks remote-source parameter values containing script tags, event handler attributes, or encoded HTML markup
  • Enforce a strict Content Security Policy that disallows inline scripts and restricts script sources to known origins
  • Disable or restrict access to the URL Handler functionality if it is not required for operational workflows
bash
# Example nginx configuration to block obvious XSS payloads in remote-source
location / {
    if ($args ~* "remote-source=[^&]*(<script|javascript:|onerror=|onload=)") {
        return 403;
    }
    add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'";
    proxy_pass http://orthanc_explorer_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeXSS

  • Vendor/TechOrthanc

  • SeverityLOW

  • CVSS Score2.1

  • EPSS Probability0.04%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityLow
  • AvailabilityNone
  • CWE References
  • CWE-79
  • Technical References
  • GitHub Issue Tracker

  • GitHub Commit Log

  • VulDB CVE Listing

  • VulDB Submission

  • VulDB Vulnerability Profile

  • VulDB CTI Analysis
  • Related CVEs
  • CVE-2026-10528: Orthanc DICOM Server Buffer Overflow

  • CVE-2026-5444: Heap Buffer Overflow Vulnerability

  • CVE-2026-5439: Orthanc ZIP Processing DoS Vulnerability

  • CVE-2026-5438: Orthanc Gzip Decompression DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English