A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-10528

CVE-2026-10528: Orthanc DICOM Server Buffer Overflow

CVE-2026-10528 is a stack-based buffer overflow vulnerability in Orthanc DICOM Server affecting versions up to 1.12.11. This flaw allows local attackers to exploit the DCMTK Parser component. Learn about affected versions and mitigation.

Published: June 4, 2026

CVE-2026-10528 Overview

CVE-2026-10528 is a stack-based buffer overflow vulnerability in Orthanc DICOM Server versions up to 1.12.11. The flaw resides in the DcmItem::read function within OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp, part of the DCMTK Parser component. An attacker with local access and low privileges can manipulate DICOM input to trigger memory corruption on the stack. The exploit has been publicly disclosed, increasing the likelihood of attempted use against unpatched installations. The maintainers have released a fix identified by patch revision bae99026ca97. The vulnerability is tracked under [CWE-119] for improper restriction of operations within the bounds of a memory buffer.

Critical Impact

Local attackers can trigger a stack-based buffer overflow in the DCMTK Parser, potentially causing denial of service in DICOM medical imaging workloads.

Affected Products

  • Orthanc DICOM Server versions up to and including 1.12.11
  • Orthanc Framework component FromDcmtkBridge.cpp
  • DCMTK Parser integration within Orthanc

Discovery Timeline

  • 2026-06-02 - CVE-2026-10528 published to NVD
  • 2026-06-02 - Last updated in NVD database

Technical Details for CVE-2026-10528

Vulnerability Analysis

The vulnerability exists in the DcmItem::read function used by Orthanc to parse DICOM (Digital Imaging and Communications in Medicine) data through the DCMTK toolkit bridge. When the parser processes a malformed DICOM item, the function writes beyond the bounds of a fixed-size stack buffer. This stack-based buffer overflow [CWE-119] can corrupt adjacent stack memory, including saved return addresses and local variables.

The attack vector is local, meaning the adversary must already have access to the host or be able to supply input that the local Orthanc process consumes. The required privileges are low, and no user interaction is needed. While the vendor-assigned impact reflects limited availability impact only, public release of exploit details raises the operational risk for healthcare environments running unpatched instances.

Root Cause

The root cause is insufficient bounds checking when DcmItem::read parses tag length fields and element data from DICOM input. Crafted length values cause the function to copy more bytes than the destination stack buffer can hold. The patch at revision bae99026ca97 introduces the necessary length validation before the read operation proceeds.

Attack Vector

An attacker with local access supplies a malformed DICOM file or stream to the Orthanc DCMTK parsing path. When DcmItem::read processes the crafted item, the stack buffer overflows. The most reliable outcome is process crash and denial of service. Exploitation for code execution depends on platform mitigations such as stack canaries, ASLR, and DEP. See the Orthanc Bug Report and the Orthanc Code Revision for technical details. No verified public proof-of-concept code is included here.

Detection Methods for CVE-2026-10528

Indicators of Compromise

  • Unexpected crashes or segmentation faults in the Orthanc service process during DICOM ingestion
  • Core dumps referencing DcmItem::read or FromDcmtkBridge.cpp in the stack trace
  • Anomalous DICOM files with malformed item length fields submitted to local ingestion paths

Detection Strategies

  • Monitor Orthanc service logs for parser errors, abnormal terminations, and restart loops tied to DICOM uploads
  • Inspect DICOM inputs for oversized or inconsistent element length fields prior to parsing
  • Correlate process crash events on hosts running Orthanc with recent file write activity in DICOM ingestion directories

Monitoring Recommendations

  • Enable verbose Orthanc logging and forward logs to a centralized analytics platform for parser-error pattern detection
  • Track integrity and provenance of DICOM files placed in watched folders or submitted via local APIs
  • Alert on repeated Orthanc process restarts or non-zero exit codes on imaging servers

How to Mitigate CVE-2026-10528

Immediate Actions Required

  • Upgrade Orthanc to a release that includes patch revision bae99026ca97 or later
  • Restrict local access to systems running Orthanc to trusted operators and service accounts only
  • Validate and sanitize DICOM inputs before they reach the Orthanc parser, especially from untrusted sources

Patch Information

The Orthanc maintainers committed the fix as revision bae99026ca97. The patch corrects bounds handling in the DcmItem::read code path used through FromDcmtkBridge.cpp. Administrators should rebuild or reinstall Orthanc from a release containing this revision. Refer to the Orthanc Code Revision for the exact source-level change.

Workarounds

  • Limit filesystem and API access to the Orthanc host so only authorized local users can submit DICOM data
  • Place Orthanc behind a hardened ingestion proxy that performs DICOM structural validation before forwarding
  • Run the Orthanc service under a least-privilege account and within a sandbox or container to contain the impact of a crash

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeBuffer Overflow

  • Vendor/TechOrthanc

  • SeverityLOW

  • CVSS Score1.9

  • EPSS Probability0.01%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityLow
  • CWE References
  • CWE-119
  • Technical References
  • Orthanc Bug Attachment

  • Orthanc Bug Report

  • Orthanc Bug Comment

  • Orthanc Code Revision

  • VulDB CVE-2026-10528

  • VulDB Submission #820766

  • VulDB Vulnerability #367636

  • VulDB CTI for #367636
  • Related CVEs
  • CVE-2026-5444: Heap Buffer Overflow Vulnerability

  • CVE-2026-10173: Orthanc Explorer 2 XSS Vulnerability

  • CVE-2026-5439: Orthanc ZIP Processing DoS Vulnerability

  • CVE-2026-5438: Orthanc Gzip Decompression DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English