# OHIF DICOM Viewer Flaw Exposes Clinician Tokens via Authentication Bypass
## The Threat
A critical server-side request forgery (SSRF) vulnerability in the Open Health Imaging Foundation's (OHIF) DICOM Web Viewer Framework allows attackers to steal authenticated clinician credentials through a crafted malicious link. The flaw exists in two default data sources—DICOMWebProxy and DICOMJSON—which fetch arbitrary URLs without validation while automatically injecting OIDC Bearer tokens into outbound requests.
An attacker can exploit this by crafting a specially designed link that tricks a clinician into clicking it. When clicked, the malicious URL is processed by vulnerable OHIF components, which then transmit the clinician's authentication token to an attacker-controlled server. Because the token is automatically injected into any request made by these data sources, an attacker gains full access to API calls and patient data accessible to that clinician.
The vulnerability is particularly dangerous in healthcare environments where imaging systems frequently process sensitive patient data, including medical scans and associated clinical records. Once an attacker obtains a valid authentication token, they can impersonate the clinician, access patient information, modify records, or pivot further into the healthcare infrastructure. The global deployment of OHIF across healthcare institutions means the attack surface is extensive, and the timing of discovery—before widespread exploitation—creates an urgent remediation window.
## Severity and Impact
| Attribute | Details |
|-----------|---------|
| CVE ID | CVE-2026-12473 |
| CVSS v3.1 Score | 8.2 (HIGH) |
| CVSS v4.0 Score | 8.3 (HIGH) |
| CVSS v3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N |
| CVSS v4.0 Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N |
| CWE Classification | CWE-918: Server-Side Request Forgery (SSRF) |
| Attack Vector | Network |
| Authentication | None required (UI interaction required) |
| User Interaction | Required (victim must click malicious link) |
| Scope | Changed |
| Confidentiality Impact | High |
| Integrity Impact | Low |
| Availability Impact | None |
## Affected Products
Open Health Imaging Foundation (OHIF)
- DICOMWebProxy (default configuration)
- DICOMJSON (default configuration)
Status: Known affected. Version 3.12.2 and later contain the fix.
## Mitigations
Immediate Action Required
1. Upgrade to patched version: Organizations must upgrade to OHIF DICOM Web Viewer Framework v3.12.2 or later, released May 18, 2026. The patch was merged into both the master and release/3.12 branches as of OHIF/Viewers#5985 and OHIF/Viewers#5978.
2. Configure authentication allowlist (if upgrade delayed): If immediate upgrading is not feasible, operators running OHIF with authentication must configure the new dangerouslyAllowedOriginsForAuthenticatedEnvironments allowlist in app-config.js. This allowlist restricts which external origins can receive authenticated requests, blocking attacker-controlled domains.
3. Remove unused data sources: Immediately audit your OHIF configuration file and remove ALL unused DICOMWebProxyDataSource and DICOMJSONDataSource configurations. If these data sources are not in active use, deleting them eliminates the attack surface entirely.
4. Network segmentation: While patches are deployed, restrict network access to OHIF instances to authenticated internal networks only. Do not expose OHIF to untrusted networks or the internet.
5. Token rotation: For healthcare organizations where authentication tokens may have been compromised, rotate OIDC Bearer tokens and review access logs for suspicious activity tied to clinician accounts.
Long-Term Hardening
## References
---
## HackWire Analysis
This vulnerability exposes a critical flaw in how medical software handles authentication by default: permissiveness over security. OHIF's decision to automatically inject OIDC tokens into all requests from DICOMWebProxy and DICOMJSON is a textbook example of a dangerous default that shifts the burden of hardening onto operators—most of whom are not security engineers.
The real-world impact is severe because healthcare imaging systems are increasingly internet-facing. Many organizations deploying OHIF assume these components run only in authenticated internal networks, but clinical workflows now routinely span remote access, cloud infrastructure, and third-party integrations. A single malicious link shared in email, chat, or a phishing campaign can instantly compromise a clinician's access token, bypassing all network segmentation and requiring no exploit kit.
What's particularly concerning is the pattern this vulnerability reflects across healthcare software: systems designed for isolated networks are now deployed in hybrid and cloud environments without corresponding security controls. The SSRF flaw itself is well-understood and preventable (validate URLs, don't auto-inject tokens into external requests), yet it shipped in the default configuration. This suggests insufficient security review before release.
The researchers' responsible disclosure (Simon Weber and Volker Schönefeld) deserves credit, but organizations should not wait for the next advisory. This vulnerability is proof that medical imaging software—which stores sensitive patient data and enables clinical decision-making—must be treated with the same security rigor as identity management systems. Healthcare institutions should immediately audit all medical software for similar SSRF, CSRF, and authentication bypass flaws. The window between disclosure and widespread exploitation is typically measured in weeks, not months.
— HackWire Editorial
---
## Related Coverage