NONE · 0

CVE-2026-40939

The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity t...

Vulnerability Description

The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is fixed in 2.1.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-40939?

CVE-2026-40939 is a documented vulnerability. The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity t...

How severe is CVE-2026-40939?

CVSS scoring is not yet available for CVE-2026-40939. Check NVD for updates.

Is there a patch for CVE-2026-40939?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.