CVE-2026-52868

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
30/06/2026
Last modified:
01/07/2026

Description

An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.