OVERVIEW CVE-2026-5663 is an OS command injection vulnerability in OFFIS DCMTK versions up to 3.7.0, specifically affecting the storescp component's executeOnReception and executeOnEndOfStudy functions in dcmnet/apps/storescp.cc. This flaw allows attackers to inject and execute arbitrary operating system commands through the affected application. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.3 (HIGH), with a network-based attack vector requiring no authentication or user interaction, making it readily exploitable. The attack has low complexity and impacts confidentiality, integrity, and availability equally. The relatively high severity is balanced somewhat by an EPSS score of 0.0176, indicating this specific CVE currently ranks higher than only 0.83 percent of all recorded vulnerabilities in terms of exploitation likelihood. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities catalog. Community attention remains minimal with a FAUCET Risk Score of 38.0 out of 100, suggesting limited public awareness or discussion. The recommended mitigation is to apply patch edbb085e45788dccaf0e64d71534cfca925784b8 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.7.0CPE matchmatch criteria | cpe:2.3:a:offis:dcmtk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.