Missing Authorization in OpenEMR - CVE-2026-33915

 

Missing Authorization in OpenEMR - CVE-2026-33915

Published: April 23, 2026


Vulnerability identifier: #VU127355
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33915
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify insurance company records.

The vulnerability exists due to missing authorization in insurance company REST API routes when handling authenticated API requests to the insurance company endpoints. A remote user can send crafted API requests to modify insurance company records.

The affected routes also expose insurance company data and insurance types without the expected administrative ACL checks.


Affected software

OpenEMR

How to mitigate CVE-2026-33915

Install security update from vendor's website.

OpenEMR - update to 8.0.0.3

External References

Related Security Bulletins