Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5663

32
FAUCET Score

OVERVIEW CVE-2026-5663 is an OS command injection vulnerability in OFFIS DCMTK versions up to 3.7.0, specifically affecting the storescp component's executeOnReception and executeOnEndOfStudy functions in dcmnet/apps/storescp.cc. This flaw allows attackers to inject and execute arbitrary operating system commands through the affected application. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.3 (HIGH), with a network-based attack vector requiring no authentication or user interaction, making it readily exploitable. The attack has low complexity and impacts confidentiality, integrity, and availability equally. The relatively high severity is balanced somewhat by an EPSS score of 0.0176, indicating this specific CVE currently ranks higher than only 0.83 percent of all recorded vulnerabilities in terms of exploitation likelihood. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities catalog. Community attention remains minimal with a FAUCET Risk Score of 38.0 out of 100, suggesting limited public awareness or discussion. The recommended mitigation is to apply patch edbb085e45788dccaf0e64d71534cfca925784b8 to remediate this issue.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.7.0CPE matchmatch criteria
cpe:2.3:a:offis:dcmtk:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.72%
Probability of exploitation in next 30 days
EPSS Percentile
75.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0172 is in the 63rd percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / DCMTK/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8
Patch
machinespirits.com / advisory/2e1627
MitigationThird Party Advisory
support.dcmtk.org / redmine/issues/1194
Issue TrackingThird Party Advisory
vuldb.com / submit/786061
Third Party AdvisoryVDB Entry
vuldb.com / vuln/355486
Third Party AdvisoryVDB Entry
vuldb.com / vuln/355486/cti
Permissions RequiredVDB Entry