Authorization bypass through user-controlled key in OpenEMR - CVE-2026-25220
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Message Center message listing functionality when handling a request with the show_all=yes URL parameter. A remote user can send a crafted request to disclose sensitive information.
The issue exposes internal messages belonging to other users, including patient-related notes and staff communications.