Free FHIR vulnerability scan
Get a free FHIR vulnerability scan funded by Cantina
Find authorization, PHI exposure, and API risks in the FHIR workflow closest to launch. Apex investigates, and Cantina security experts verify every finding.
- Research
- 6 public FHIR advisories
- Validation
- Benchmarked against expert human auditors
- Ecosystem
- Supporting CMS Health Tech Ecosystem participants
Claim your vulnerability scan
Tell us about your FHIR workflow
Takes a minute. A Cantina team member will follow up with a clear next step.
Fit, scope, timing, and availability are confirmed after qualification.
Scan process
From application to verified fixes
One focused vulnerability scan. Three clear steps.
- 01
Share your workflow
Tell us what you are launching and where you want the scan focused.
- 02
We run the scan
Apex investigates the authorized environment, and Cantina security experts validate every finding.
- 03
Fix and verify
Receive prioritized fixes, then have Cantina verify that the remediation holds.
Apex FHIR research
Six CVEs in one widely used FHIR server
Apex, Cantina’s autonomous OffSec agent, traced authenticated requests across OAuth discovery, credentialed data exchange, import and export jobs, and the analytical warehouse. The investigation led to six public security advisories.
-
CVE-2026-47664
01TrustLaunder
A caller-controlled URL could receive OAuth credentials and place attacker-controlled data in the analytical warehouse.
-
CVE-2026-47663 / 47660
02Authorization and OAuth boundaries
Scope enforcement and OAuth discovery paths exposed access beyond the workflow’s intended trust boundary.
-
CVE-2026-47662 / 47661 / 47659
03Bulk Data and warehouse access
Export, import, and staging paths could expose bearer tokens or reach patient records outside the intended directory.