Path traversal in OpenEMR - CVE-2026-24488
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in the EtherFaxActions sendFax endpoint when handling user-supplied file paths. A remote user can send a specially crafted request with an arbitrary file path to disclose sensitive information.
Only instances with the Fax/SMS module enabled are vulnerable.