FUJIFILM Healthcare Americas got ICSMA-25-233-01 for its Synapse Mobility enterprise imaging viewer, versions 8.0 through 8.1.1. CVE-2025-54551, external control of an assumed-immutable web parameter. In plain terms, a logged-in user with low privileges edits a search parameter and reaches imaging and patient records their role was never supposed to show them.

The defect belongs to a broad class in which an application decides what a user may see by trusting a value the user's own client supplied. A parameter that names a record or a scope is treated as fixed once issued, yet nothing on the server stops the client from returning a different one. When the check that grants access runs only at login and not again on each request, altering that value quietly widens what the session can reach.

For an enterprise imaging viewer the records past that boundary are studies and identifiers belonging to patients the logged-in user has no clinical relationship with. A horizontal break of this shape crashes nothing and announces nothing, which makes it a compliance problem as much as a security one; access that leaves no trace can persist unnoticed.

Base score 4.3, which undersells how it feels to a compliance team. This is a horizontal access-control break, not a crash. Fixed in 8.2, with interim mitigations to disable search or uncheck the plain-text accession number option. Christopher Alejandro of Moroco reported it.

Authorization flaws of this shape rank among the most common findings in web-facing clinical software because they hide inside ordinary features. A search field, a document link or a record identifier all pass values back to the server, and each is a chance for the same mistake. They also slip past automated scanners, since the request itself looks legitimate.

Assumed-immutable is the phrase to keep. Every parameter a client sends back is one the client can change, so if your authorization only checks the front door, the search box is a side entrance.