VORANT. Threat Intelligence Sign in Get the full feed

Asseco ADMX hospital information system contained an authentication bypass allowing…

high vulnerability healthcare

Asseco ADMX hospital information system contained an authentication bypass allowing logged-in patients to access other patients' medical records via URL manipulation; fixed in v6.09.01.62.

CERT Polska coordinated disclosure of CVE-2025-4596, a vulnerability in Asseco ADMX hospital information system software used for processing medical records. The flaw allows authenticated patients to access medical files belonging to other patients by manipulating GET parameters containing document IDs. This represents an insecure direct object reference (IDOR) vulnerability that breaks patient confidentiality protections required under healthcare privacy regulations.

The vendor has released version 6.09.01.62 which remediates the issue. Healthcare organizations running ADMX should prioritize patching given the sensitivity of patient medical records and potential regulatory implications of unauthorized access to protected health information.

The vulnerability was responsibly disclosed by security researcher Wiktor Mróz and coordinated through CERT Polska's vulnerability disclosure process.

Mentioned in this report

Vulnerabilities CVE-2025-4596

Source reporting: https://cert.pl/en/posts/2026/01/CVE-2025-4596

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free