Missing Authorization in OpenEMR - CVE-2026-33305

 

Missing Authorization in OpenEMR - CVE-2026-33305

Published: April 23, 2026


Vulnerability identifier: #VU127325
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33305
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify configuration data.

The vulnerability exists due to missing authorization in the FaxSMS AppDispatch constructor and action dispatch mechanism when handling requests with the _ACTION_COMMAND parameter. A remote user can send a specially crafted request to disclose sensitive information and modify configuration data.

Only installations with the optional oe-module-faxsms module enabled are vulnerable.


Affected software

OpenEMR

How to mitigate CVE-2026-33305

Install security update from vendor's website.

OpenEMR - update to 8.0.0.2

External References

Related Security Bulletins