Improper Certificate Validation in OpenEMR - CVE-2025-67752

 

Improper Certificate Validation in OpenEMR - CVE-2025-67752

Published: April 23, 2026


Vulnerability identifier: #VU127252
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-67752
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to intercept, read, and modify encrypted communications.

The vulnerability exists due to improper certificate validation in the oeHttp and oeOAuth HTTP client wrappers when making external HTTPS requests. A remote attacker can perform a man-in-the-middle attack with a fake certificate to intercept, read, and modify encrypted communications.

The issue affects external service integrations including government healthcare APIs and OAuth flows, potentially exposing protected health information and tokens.


Affected software

OpenEMR

How to mitigate CVE-2025-67752

Install security update from vendor's website.

OpenEMR - update to 7.0.4

External References

Related Security Bulletins