security advisorydebianprivilege escalation
Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access. For Debian 11 bullseye, this problem has been fixed in version. Debian LTS Advisory DLA-4494-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Paride Legovini February 28, 2026 https://wiki.debian.org/LTS Package : orthanc Version : 1.9.2+really1.9.1+dfsg-1+deb11u2 CVE ID : CVE-2025-15581 Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access. For Debian 11 bullseye, this problem has been fixed in version 1.9.2+really1.9.1+dfsg-1+deb11u2. We recommend that you upgrade your orthanc packages. For the detailed security status of orthanc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/orthanc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Orthanc in Debian LTS has an important Privilege Escalation issue fixed in DLA-4494-1. Upgrade recommended.. Debian Security, Privilege Escalation, Orthanc, HTTP Authentication. . Severity: Important. LinuxSecurity.com Team
Feb 28, 2026
•Important
Debian LTS