SQL injection in OpenEMR - CVE-2026-33909

 

SQL injection in OpenEMR - CVE-2026-33909

Published: April 23, 2026


Vulnerability identifier: #VU127343
CSH Severity: Low
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33909
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SQL commands.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in the MedEx recall/reminder processing code when processing MedEx preference values or external MedEx API response data. A remote privileged user can supply crafted input that is concatenated into SQL queries to execute arbitrary SQL commands.

MedEx must be explicitly enabled, and exploitation depends on controlling MedEx preference data or the MedEx API connection.


Affected software

OpenEMR

How to mitigate CVE-2026-33909

Install security update from vendor's website.

OpenEMR - update to 8.0.0.3

External References

Related Security Bulletins