SQL injection in OpenEMR - CVE-2026-25746
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information, modify database contents, or cause a denial of service.
The vulnerability exists due to SQL injection in the prescription listing functionality when handling the user-supplied sort parameter. A remote user can send a specially crafted request to disclose sensitive information, modify database contents, or cause a denial of service.
The issue affects the prescription controller path and requires the standard patients rx ACL permission.