Direct Request ('Forced Browsing') in OpenEMR - CVE-2026-34056
Published: April 30, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper authorization in erx_logview.php when handling requests for Ensora eRx error logs. A remote user can send a crafted request to disclose sensitive information.
The issue allows low-privilege users to view and download admin-only Ensora eRx error logs without proper authorization checks.