# Asseco InfoMedica flaws enable privilege escalation

Published: 2026-01-08 · Severity: high · Sectors: healthcare
Canonical: https://vorant.io/reports/b63fff22-e68a-5f3c-ba2a-7427685c7274/asseco-infomedica-flaws-enable-privilege-escalation

> Two chained vulnerabilities in Asseco InfoMedica Plus allow low-privileged users to extract and decode administrator passwords, enabling privilege escalation in healthcare management systems.

CERT Polska coordinated disclosure of two vulnerabilities in Asseco InfoMedica Plus, a healthcare management platform handling administrative and medical tasks. CVE-2025-8306 allows low-privileged users to obtain encoded passwords of other accounts, including the main administrator, due to inadequate access control granularity. CVE-2025-8307 involves passwords stored in an encoded rather than hashed format, with the decoding algorithm embedded in client-side software.

When chained together, these vulnerabilities enable an authenticated attacker with low privileges to escalate to administrator access. The attacker first leverages CVE-2025-8306 to extract encoded passwords from the database, then uses the client-side algorithm (CVE-2025-8307) to decode them in plaintext. Both vulnerabilities have been patched in versions 4.50.1 and 5.38.0.

The disclosure was handled through CERT Polska's coordinated vulnerability disclosure process, with credit to researcher Maciej Kazulak for responsible reporting. Healthcare organizations using Asseco InfoMedica Plus should prioritize patching to these fixed versions.

## Mentioned in this report

- Vulnerabilities: CVE-2025-8306, CVE-2025-8307

Source reporting: https://cert.pl/en/posts/2026/01/CVE-2025-8306

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b63fff22-e68a-5f3c-ba2a-7427685c7274/asseco-infomedica-flaws-enable-privilege-escalation.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
