CVE-2026-2034 is a buffer overflow vulnerability in Sante DICOM Viewer Pro, specifically affecting its DCM file parsing. This flaw allows remote attackers to achieve arbitrary code execution by tricking a user into opening a malicious DCM file or visiting a malicious web page. The vulnerability carries a high CVSS score of 7.8, indicating a significant risk. It requires user interaction (UI:R) but has low attack complexity (AC:L), and successful exploitation can lead to high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB: None), and it is not listed in CISA's KEV catalog, suggesting it is not actively exploited in the wild. Community discussion is minimal, with only one mention found.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.2.7CPE matchmatch criteria | cpe:2.3:a:santesoft:dicom_viewer_pro:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.