Cross-site scripting in OpenEMR - CVE-2026-32124

 

Cross-site scripting in OpenEMR - CVE-2026-32124

Published: April 23, 2026


Vulnerability identifier: #VU127308
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-32124
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in a victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in the dynamic code picker code description rendering path when displaying stored code descriptions returned by the AJAX endpoint. A remote user can create or edit a code entry with a malicious description to execute arbitrary script in a victim's browser.

User interaction is required when a victim opens a form or screen that uses the dynamic code picker.


Affected software

OpenEMR

How to mitigate CVE-2026-32124

Install security update from vendor's website.

OpenEMR - update to 8.0.0.1

External References

Related Security Bulletins