Improper Authentication in OpenEMR - CVE-2026-24898

 

Improper Authentication in OpenEMR - CVE-2026-24898

Published: April 23, 2026


Vulnerability identifier: #VU127298
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-24898
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and perform unauthorized actions on the MedEx platform.

The vulnerability exists due to improper authentication in the MedEx callback endpoint when handling a POST request containing a callback_key parameter. A remote attacker can send a specially crafted request to disclose sensitive information and perform unauthorized actions on the MedEx platform.

Only installations with the MedEx service enabled are vulnerable.


Affected software

OpenEMR

How to mitigate CVE-2026-24898

Install security update from vendor's website.

OpenEMR - update to 8.0.0

External References

Related Security Bulletins