Improper access control in OpenEMR - CVE-2026-25127

 

Improper access control in OpenEMR - CVE-2026-25127

Published: April 23, 2026


Vulnerability identifier: #VU127261
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25127
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the Care Coordination module endpoint when handling requests to the encountermanager URL. A remote user can send a crafted request with a valid low-privileged session cookie to disclose sensitive information.

The issue affects access to data that should be restricted by the configured access control list for the module.


Affected software

OpenEMR

How to mitigate CVE-2026-25127

Install security update from vendor's website.

OpenEMR - update to 8.0.0

External References

Related Security Bulletins