Authorization bypass through user-controlled key in OpenEMR - CVE-2026-25930
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in interface/forms/LBF/printable.php when handling requests with user-supplied formid, visitid, and patientid values. A remote user can send a specially crafted request to disclose sensitive information.
The issue affects the printable view for layout-based forms and allows enumeration of form identifiers to access other patients' encounter forms.