Improper access control in OpenEMR - CVE-2026-32123
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the encounter sensitivity logic in EncounterService.php when handling group encounters. A remote user can access a sensitive group encounter or its forms to disclose sensitive information.
Only group encounters that use sensitivity flags are affected, because sensitivity is stored in form_groups_encounter but the check consults only form_encounter.