Orthanc DICOM Server Heap Out-of-Bounds Write via Integer Overflow in Image Decoding (CVE-2026-87020)
First seen Sep 11, 2026 · Updated Sep 11, 2026 · CVSS 8.1
Orthanc DICOM Server versions prior to 1.13.0 contain an integer overflow vulnerability in pitch/buffer-size computation that leads to a heap out-of-bounds write when decoding attacker-supplied PNG or JPEG images. An authenticated remote attacker can exploit this to crash the Orthanc process, causing a denial-of-service condition affecting medical imaging availability.
Technical Analysis
CVE-2026-87020 (CWE-190, CVSS v3.1 8.1) is an integer overflow occurring during buffer-size and pitch calculations when Orthanc parses attacker-supplied PNG or JPEG image data, resulting in a heap out-of-bounds write. Exploitation requires low-privilege authentication and no user interaction, and can be triggered remotely over the network (AV:N, PR:L, UI:N), causing the Orthanc process to crash and disrupting availability of DICOM imaging services. No known public exploitation has been reported to CISA at this time. This vulnerability does not have plausible direct relevance to AI agent systems, as Orthanc is a medical imaging server rather than infrastructure typically embedded in agent/LLM tool-use pipelines; however, healthcare organizations that integrate Orthanc into automated imaging-analysis or agentic diagnostic workflows should be aware that a crash could disrupt those pipelines' data sources.
Affected Systems
Orthanc DICOM Server versions prior to 1.13.0, deployed worldwide primarily in Healthcare and Public Health sector environments
Indicators of Compromise
- No specific IOCs published; vulnerability tracked as CVE-2026-87020
Remediation Steps
- 1
Upgrade Orthanc
Update Orthanc DICOM Server to version 1.13.0 or later, available at https://orthanc.uclouvain.be/downloads/index.html
- 2
Network segmentation
Minimize network exposure for control system devices; ensure Orthanc servers are not accessible directly from the internet and are placed behind firewalls, isolated from business networks
- 3
Secure remote access
Use VPNs or other secure remote access methods when remote connectivity to imaging systems is required, keeping VPN software updated
- 4
Monitor and report
Monitor for abnormal crashes or DoS conditions on Orthanc instances and report suspected malicious activity to CISA for tracking
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.