Researcher Identified Vulnerabilities in DCM4CHE Toolkit
The flaws could allow attackers to delete or fabricate patient imaging scans and patient records.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you trust the security of digital systems holding your sensitive medical records?
Security researcher Abhinav Agarwal has discovered critical vulnerabilities within the open-source DCM4CHE medical imaging toolkit. These flaws could potentially allow unauthorized users to delete patient scans or inject fabricated studies into medical systems.
Why it matters
The security gaps represent a significant risk to healthcare infrastructure, as they could enable attackers to bypass authentication to manipulate sensitive DICOM and HL7 patient data.
The vulnerabilities affect software including Docker images labeled 5.35.2 and below. Researchers found that flaws could trigger denial-of-service states through infinite loops or inefficient boundary scanning.
The players
Abhinav Agarwal
He is the security researcher who identified the vulnerabilities in the DCM4CHE software.
Vanderbilt University Medical Center
This institution is a reported user of the DCM4CHE toolkit within the United States.
Cybersecurity and Infrastructure Security Agency
This federal agency is currently coordinating with the researcher regarding an upcoming advisory.
The details
The vulnerabilities allow for the reassignment of imaging studies to incorrect patient identities and provide unauthorized access to critical medical interfaces. While the tests were conducted in isolated environments using synthetic patient information, the software remains in use by commercial vendors such as MedDream, Mesys, and Comiere.
Timeline
Vanderbilt University Medical Center reported using the software in 2025.
Four security advisories were published on GitHub on Monday, September 21, 2026.
Two additional findings remained in draft status on Wednesday, September 23, 2026.
The Tech Race
This situation follows a pattern set by the 2021 Log4j vulnerability discovery regarding the disclosure of critical flaws in widely used open-source libraries. It underscores the ongoing industry struggle to secure foundational codebases against potential exploitation in complex medical environments.
Healthcare providers relying on DCM4CHE-based systems may face increased maintenance requirements to patch their imaging infrastructure. Patients and staff should remain aware that these security flaws could impact the integrity of medical record systems if left unaddressed.
The takeaway
Organizations utilizing open-source medical tools must prioritize rapid software patching to defend against potential data fabrication or unauthorized access. Regular security audits of third-party dependencies are essential to maintaining the integrity of patient diagnostic information.
What happens next
The U.S. Cybersecurity and Infrastructure Security Agency is expected to issue an official advisory, and the researcher anticipates the future assignment of CVE identifiers for the vulnerabilities.
Further reading
For more information on current digital threats, visit the Cybersecurity section.
Source note: This article includes information reported by DataBreachToday.
Live Poll
Do you trust the security of digital systems holding your sensitive medical records?










