| CVE ID | CVE-2025-4596 |
| Publication date | 08 January 2026 |
| Vendor | Asseco |
| Product | AMDX |
| Vulnerable versions | All before 6.09.01.62 |
| Vulnerability type (CWE) | Authorization Bypass Through User-Controlled Key (CWE-639) |
| Report source | Report to CERT Polska |
Description
Asseco ADMX software is a hospital information system (HIS) used for processing medical records. CERT Polska has received a report about vulnerability in ADMX software and participated in coordination of its disclosure.
The vulnerability CVE-2025-4596 allows logged in patients to access medical files belonging to other patients through manipulation of GET arguments containing document IDs. This issue has been fixed in 6.09.01.62 version of ADMX.
Credits
We thank Wiktor Mróz for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.