CVE-2026-58126

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remote code execution as NT Authority\SYSTEM upon service restart.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hyland:pacsgear:*:*:*:*:*:*:*:*

History

09 Jul 2026, 02:38

Type Values Removed Values Added
First Time Hyland pacsgear
Hyland
CPE cpe:2.3:a:hyland:pacsgear:*:*:*:*:*:*:*:*
References () https://gist.github.com/VAMorales/6dc232729cdd517fa30d581fbcd98d8f - () https://gist.github.com/VAMorales/6dc232729cdd517fa30d581fbcd98d8f - Exploit, Third Party Advisory
References () https://www.hyland.com/en/solutions/products/pacsgear - () https://www.hyland.com/en/solutions/products/pacsgear - Product
References () https://www.vulncheck.com/advisories/pacsgear-pacs-scan-unauthenticated-rce-via-net-remoting-tcp-service - () https://www.vulncheck.com/advisories/pacsgear-pacs-scan-unauthenticated-rce-via-net-remoting-tcp-service - Third Party Advisory, VDB Entry

01 Jul 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-01 16:16

Updated : 2026-07-09 02:38


NVD link : CVE-2026-58126

Mitre link : CVE-2026-58126

CVE.ORG link : CVE-2026-58126


JSON object : View

Products Affected

hyland

  • pacsgear
CWE
CWE-306

Missing Authentication for Critical Function

CWE-502

Deserialization of Untrusted Data