Improper access control in OpenEMR - CVE-2026-24896
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the edih_main.php endpoint and EDI log viewing functionality when handling crafted GET requests with the log_select parameter. A remote user can send a specially crafted request to disclose sensitive information.
The issue allows authenticated low-privilege roles, such as receptionist, to access EDI log files outside the intended GUI-enforced permission boundaries.