Improper access control in OpenEMR - CVE-2026-25127
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Care Coordination module endpoint when handling requests to the encountermanager URL. A remote user can send a crafted request with a valid low-privileged session cookie to disclose sensitive information.
The issue affects access to data that should be restricted by the configured access control list for the module.