# Asseco ADMX hospital information system contained an authentication bypass allowing…

Published: 2026-01-08 · Severity: high · Sectors: healthcare
Canonical: https://vorant.io/reports/5203f104-49ef-480d-b366-46ea01879b4f/asseco-admx-hospital-information-system-contained-an-authentication-bypass

> Asseco ADMX hospital information system contained an authentication bypass allowing logged-in patients to access other patients' medical records via URL manipulation; fixed in v6.09.01.62.

CERT Polska coordinated disclosure of CVE-2025-4596, a vulnerability in Asseco ADMX hospital information system software used for processing medical records. The flaw allows authenticated patients to access medical files belonging to other patients by manipulating GET parameters containing document IDs. This represents an insecure direct object reference (IDOR) vulnerability that breaks patient confidentiality protections required under healthcare privacy regulations.

The vendor has released version 6.09.01.62 which remediates the issue. Healthcare organizations running ADMX should prioritize patching given the sensitivity of patient medical records and potential regulatory implications of unauthorized access to protected health information.

The vulnerability was responsibly disclosed by security researcher Wiktor Mróz and coordinated through CERT Polska's vulnerability disclosure process.

## Mentioned in this report

- Vulnerabilities: CVE-2025-4596

Source reporting: https://cert.pl/en/posts/2026/01/CVE-2025-4596

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5203f104-49ef-480d-b366-46ea01879b4f/asseco-admx-hospital-information-system-contained-an-authentication-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
