Insufficient Logging in OpenEMR - CVE-2025-32967
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to weaken auditability of password change actions.
The vulnerability exists due to insufficient logging in the client-side log viewer and related password change logging functionality when handling password change events through the user interface. A remote user can change a password through the application interface to weaken auditability of password change actions.
Server-side log entries may appear only as vague update events and may not clearly identify the action as a password change.