Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack user sessions and gain unauthorized access to the PACS system.
Affected vendor
Structured metadata unavailable
Affected product
Product metadata unavailable
Coverage
No structured product entries
CVSS
6.9
MEDIUM
Published
Apr 29, 2026

