


Perceptive Security
SOC/SIEM Consultancy

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by explo…
Published:
30 juni 2026 om 22:00:00
Alert date:
1 juli 2026 om 17:07:03
Source:
nvd.nist.gov
Critical Infrastructure, Enterprise Applications, Zero-Day Vulnerabilities
PACSgear PACS Scan version 5.2.1 contains a critical unauthenticated remote code execution vulnerability tracked as CVE-2026-58126. The flaw stems from an exposed .NET Remoting TCP service running on port 22222 via PGImageExchQueue.exe, which requires no authentication. Attackers can exploit this to read and write arbitrary files on the target system. By chaining the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, attackers can achieve full SYSTEM-level code execution upon service restart. The vulnerability requires no credentials, making it highly accessible to remote threat actors. The affected software is a medical imaging product distributed by Hyland under the PACSgear brand. Exploitation could have serious consequences in healthcare environments where PACS systems manage sensitive medical imaging data. A proof-of-concept is publicly available on GitHub, increasing the risk of active exploitation.
Technical details
Mitigation steps:
Affected products:
PACSgear PACS Scan 5.2.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-58126
https://gist.github.com/VAMorales/6dc232729cdd517fa30d581fbcd98d8f
https://www.hyland.com/en/solutions/products/pacsgear
https://www.vulncheck.com/advisories/pacsgear-pacs-scan-unauthenticated-rce-via-net-remoting-tcp-service
Related CVE's:
Related threat actors:
IOC's:
port:22222, PGImageExchQueue.exe, PGImageExchangeQueueSvc.exe, CRYPTSP.DLL
This article was created with the assistance of AI technology by Perceptive.
