PT-2026-45794 · Spacelabs Healthcare · Sentinel

·

CVE-2026-0611

·

Published

2026-06-02

·

Updated

2026-06-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spacelabs Healthcare Sentinel versions 10.5.x and higher Spacelabs Healthcare Sentinel versions prior to 11.6.0
Description An unauthenticated remote code execution issue exists via a deprecated .NET Remoting HTTP channel exposed on port 8989. This allows attackers to perform arbitrary file read and write operations by providing valid .NET URI endpoints. By writing ASPX webshells to the IIS wwwroot directory, an attacker can achieve remote code execution on the system. This requires that port 8989 has been explicitly made network-accessible through configuration or network policy changes, as it is not exposed by default.
Recommendations Update Spacelabs Healthcare Sentinel to version 11.6.0 or later. Restrict network access to port 8989 to prevent unauthorized access to the .NET Remoting channel.

Exploit

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0611

Affected Products

Sentinel