---
id: CVE-2025-8306
title: >-
  Asseco InfoMedica is a comprehensive solution used to manage both
  administrative and medical tasks in the healthcare sector
summary: >-
  Asseco InfoMedica is a comprehensive solution used to manage both
  administrative and medical tasks in the healthcare sector. A low privileged
  user is able to obtain encoded passwords of all other accounts (including main
  administrator) d…
severity: none
cwe:
  - CWE-1220
published: '2026-01-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8306'
references:
  - url: 'https://cert.pl/en/posts/2026/01/CVE-2025-8306/'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.00153
epssPercentile: 0.03792
ingestedAt: '2026-09-30T22:27:27.737Z'
---

## Overview

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. A low privileged user is able to obtain encoded passwords of all other accounts (including main administrator) due to lack of granularity in access control. 
Chained exploitation of this vulnerability and CVE-2025-8307 allows an attacker to escalate privileges. This vulnerability has been fixed in versions 4.50.1 and 5.38.0

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
