Information disclosure in OpenEMR - CVE-2026-24487
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the FHIR CareTeam resource endpoint when handling requests with patient-scoped FHIR tokens. A remote user can send a request to the CareTeam endpoint without a patient parameter to disclose sensitive information.
Exploitation requires the FHIR API to be enabled and a valid patient-scoped FHIR OAuth2 token.