FUJIFILM Healthcare Americas got ICSMA-25-233-01 for its Synapse Mobility enterprise imaging viewer, versions 8.0 through 8.1.1. CVE-2025-54551, external control of an assumed-immutable web parameter. In plain terms, a logged-in user with low privileges edits a search parameter and reaches imaging and patient records their role was never supposed to show them.
Base score 4.3, which undersells how it feels to a compliance team. This is a horizontal access-control break, not a crash. Fixed in 8.2, with interim mitigations to disable search or uncheck the plain-text accession number option. Christopher Alejandro of Moroco reported it.
Assumed-immutable is the phrase to keep. Every parameter a client sends back is one the client can change, so if your authorization only checks the front door, the search box is a side entrance.