dcm4chee-arc-light
Remote Code Execution via XSLT Attribute-Coercion Injection
The archive applies attribute-coercion rules that transform DICOM objects as they are stored, queried, or retrieved, and such a rule may name an XSLT stylesheet by URI. The stylesheet is compiled with an XML transformer factory left at its permissive defaults, so the stylesheet may call Java extension functions. An attacker able to write archive configuration can install such a rule and have arbitrary operating-system commands run as the archive service account the next time the transform fires on ordinary DICOM traffic, which a single store or query is enough to trigger.
This advisory contains limited information during coordinated disclosure. Please check back later for full details.
Description
dcm4chee-arc-light is the DICOM archive and image manager of the dcm4che project, used by hospitals, research groups, and imaging vendors as open infrastructure for storing and exchanging medical images. We appreciate the project's long-running work on that infrastructure and the care its maintainers took over this report. We reported this finding privately to J4Care in June 2026; they responded constructively and released a fix.
The fix enables JAXP secure processing by default on the shared transformer factory in the dcm4che library, which disables Java extension functions, and restricts the protocols an external stylesheet may be loaded over. Because the factory is shared, the change covers every consumer of the library rather than the coercion path alone. This is a coordinated disclosure; the full technical writeup follows once the remediation window closes.
Impact
- Code execution in the archive process carries the archive's own access to the imaging record it holds. The process is the custodian of the stored DICOM objects and of the database that indexes them, so studies and the patient identifiers attached to them can be read, altered, or deleted, and the credentials the archive holds for its own backing services are readable in that context.
- Severity is rated against the deployment the project's own documentation presents first, in which the configuration interface answers without authentication. Where the secured build is deployed instead, the configuration interface requires only the base role that the shipped low-privilege account already holds, so the chain remains reachable by any authenticated user rather than being closed.
Mitigation
Upgrade to dcm4chee-arc-light 5.35.0 or later, which enables JAXP secure processing on the XSLT path. Until upgraded, operators can reduce exposure by starting the application server with the JVM property jdk.xml.enableExtensionFunctions set to false, which stops the command-execution step without disabling attribute coercion, and by restricting the configuration and control interfaces, the DICOM port, and the LDAP configuration backend to trusted networks.
References
How We Can Help
Who We Are
The security researchers behind this advisory.

Dr. rer. nat. Simon Weber
Senior Pentester & MedSec Researcher
I evaluate your SaMD with the same industry-defining security insight I contributed to the BAK MV for the revision of the B3S standard.
- PhD on Hospital Cybersecurity
- Critical vulnerabilities found in hospital systems
- Alumni of THB MedSec Research Group
- gematik Security Hero

Dipl.-Inf. Volker Schönefeld
Senior Application Security Expert
As a former CTO and developer turned pentester, I work alongside your team to uncover vulnerabilities and find solutions that fit your architecture.
- 20+ years as CTO, 50M+ app downloads
- Architected and secured large-scale IoT fleets
- Certified Web Exploitation Specialist
- gematik Security Hero
Looking for a Penetration Test?
Machine Spirits specializes in security assessments for medical devices and healthcare IT. From MDR penetration testing to C5 cloud compliance, we help MedTech companies meet regulatory requirements.
