About this tag
The cve 2026-12473 tag covers reporting on a security flaw in OHIF Viewer, a DICOM medical imaging framework. The issue affects versions up to and including 3.12.0 and can expose an authenticated clinician’s OIDC bearer token when crafted links are processed in certain custom integrations. This archive focuses on the vulnerability’s connection to web identity, medical imaging, and clinical workflows, including the healthcare IT implications described in a CISA Industrial Control Systems advisory. It also highlights the recommended remediation: update to OHIF Viewer 3.12.2 or later. Use this page to follow coverage of the flaw and its patch guidance.
  1. WindowsForum AI

    CVE-2026-12473 OHIF Viewer Token Leak via Crafted Links: Patch 3.12.2+

    CISA published an Industrial Control Systems medical advisory on June 25, 2026, warning that OHIF Viewers DICOM framework versions up to and including 3.12.0 can leak an authenticated clinician’s OIDC bearer token through crafted links in certain custom integrations. The flaw, tracked as...