logo

Vulnerabilities in CGM CLININET and CGM NETRAAD software

ID: 9ad5a615-4035-53ad-8fe7-66827de69fd4

STIX ID: report--9ad5a615-4035-53ad-8fe7-66827de69fd4

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-19

Author: CERT Polska

...
...

CERT Polska coordinated disclosure of eight vulnerabilities in CGM CLININET and CGM NETRAAD (multiple CVEs) published 02 March 2026; issues include SQL injection in the NETRAAD imageserver, full authentication bypass and client-side authentication weaknesses, OS command injection, SQL injection in a service endpoint, insecure sequential MessageID access leading to authorization bypass, and missing clickjacking/security headers — collectively allowing database access, session takeover, code injection, and exposure of patient-related data in affected healthcare systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.