Incorrect authorization in OpenEMR - CVE-2026-33302

 

Incorrect authorization in OpenEMR - CVE-2026-33302

Published: April 30, 2026


Vulnerability identifier: #VU128547
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33302
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass authorization restrictions.

The vulnerability exists due to incorrect authorization in AclMain::zhAclCheck() when evaluating module ACL permissions. A remote user can rely on a group "allow" entry while an explicit user or group "deny" exists to bypass authorization restrictions.

Exploitation requires authentication and that the affected feature uses module ACL checks through zhAclCheck().


Affected software

OpenEMR

How to mitigate CVE-2026-33302

Install security update from vendor's website.

OpenEMR - update to 8.0.0.2

External References

Related Security Bulletins