Authorization bypass through user-controlled key in OpenEMR - CVE-2026-27943

 

Authorization bypass through user-controlled key in OpenEMR - CVE-2026-27943

Published: April 23, 2026


Vulnerability identifier: #VU127292
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27943
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to authorization bypass through a user-controlled key in interface/forms/eye_mag/view.php when handling a user-supplied form_id parameter. A remote user can supply another patient's form ID to disclose sensitive information.

The issue affects the eye exam view path and may switch the active patient in the session in some flows.


Affected software

OpenEMR

How to mitigate CVE-2026-27943

Install security update from vendor's website.

OpenEMR - update to 8.0.0

External References

Related Security Bulletins