Authorization bypass through user-controlled key in OpenEMR - CVE-2026-25929
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the document controller patient_picture context when handling requests with a user-supplied patient_id. A remote user can send a crafted request with another patient's ID to disclose sensitive information.
The issue affects retrieval of patient photos associated with other patient records.