# Asseco InfoMedica Plus healthcare management software fixed two chained vulnerabilities…

Published: 2026-01-08 · Severity: high · Sectors: healthcare
Canonical: https://vorant.io/reports/743c4558-8ca9-4baf-80da-feb758ffb089/asseco-infomedica-plus-healthcare-management-software-fixed-two-chained

> Asseco InfoMedica Plus healthcare management software fixed two chained vulnerabilities allowing low-privileged users to extract and decode passwords, enabling privilege escalation to administrator.

CERT Polska coordinated disclosure of two critical vulnerabilities in Asseco InfoMedica Plus, a comprehensive healthcare management platform used for administrative and medical operations. CVE-2025-8306 permits low-privileged users to extract encoded passwords of other accounts, including the main administrator, due to insufficient access control granularity. CVE-2025-8307 involves insecure storage of user passwords in an encoded format within the database, where the decoding algorithm is embedded in the client-side application.

When chained together, these vulnerabilities enable a straightforward privilege escalation attack path: a low-privileged attacker can retrieve encoded administrator credentials via the access control flaw, then decode them using the client-side algorithm to gain full administrative access to the healthcare system. Both vulnerabilities have been remediated in versions 4.50.1 and 5.38.0.

The disclosure was handled responsibly through CERT Polska's coordinated vulnerability disclosure process, with credit to security researcher Maciej Kazulak for the initial report. Organizations running Asseco InfoMedica Plus should prioritize patching to the fixed versions immediately given the high risk of privilege escalation in healthcare environments where data sensitivity and system availability are critical.

## Mentioned in this report

- Vulnerabilities: CVE-2025-8306, CVE-2025-8307

Source reporting: https://cert.pl/en/posts/2026/01/CVE-2025-8306

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/743c4558-8ca9-4baf-80da-feb758ffb089/asseco-infomedica-plus-healthcare-management-software-fixed-two-chained.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
