Improper Authentication in OpenEMR - CVE-2026-24898
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information and perform unauthorized actions on the MedEx platform.
The vulnerability exists due to improper authentication in the MedEx callback endpoint when handling a POST request containing a callback_key parameter. A remote attacker can send a specially crafted request to disclose sensitive information and perform unauthorized actions on the MedEx platform.
Only installations with the MedEx service enabled are vulnerable.