PT-2026-45843 · Medplum · Medplum

·

CVE-2026-49120

·

Published

2026-06-02

·

Updated

2026-06-04

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Medplum versions prior to 5.1.14
Description An issue in the subscription worker allows authenticated users to perform unauthorized internal network requests. By creating FHIR Subscription resources with arbitrary endpoint URLs, attackers can target internal addresses such as cloud instance metadata services, internal databases, or container orchestration endpoints. This can lead to the exfiltration of IAM credentials and patient health records through the POST body, which contains full FHIR resource payloads. Server-Side Request Forgery (SSRF) is a flaw where an attacker can force a server to make requests to an unintended location.
Recommendations Update to version 5.1.14 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49120

Affected Products

Medplum