ID:12882 - Exploit for Path traversal in OpenEMR - CVE-2026-24849
Published: August 6, 2026
OpenEMR
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control and path traversal in the disposeDocument() method of the oe-module-faxsms EtherFaxActions controller when handling a user-supplied file_path parameter in a download request. A remote user can send a specially crafted request to disclose sensitive information.
Exploitation requires a valid account, the Fax SMS module to be enabled, and EtherFax to be configured as the fax provider.