CVE-2026-40939 Details
Description
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is fixed in 2.1.0.
A vulnerability exists in the Data Sharing Framework (DSF) versions prior to 2.1.0, specifically within the DSF FHIR Server and DSF BPE Server when OpenID Connect (OIDC) authentication is enabled. The issue arises because OIDC-authenticated sessions lacked a maximum inactivity timeout, allowing sessions to persist indefinitely after login, even after the OIDC access token had expired. This flaw could lead to unauthorized access, as another user could potentially use the same browser to access the DSF UI with the previous user's permissions. This vulnerability is particularly concerning in hospital environments with shared workstations, where it could be exploited to gain access to sensitive information or perform actions on behalf of the original user.
Users can upgrade to DSF version 2.1.0, which addresses this vulnerability by introducing a configurable session timeout for OIDC logins and tying session lifetime to the OIDC access token's validity. Instructions for upgrading to DSF 2.1.0 are available on the DSF website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 21, 2026CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Data Sharing Framework | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | New CVE Received | [email protected] |
Volerion