Improper access control in OpenMRS - #VU129552
Published: January 30, 2025 / Updated: May 4, 2026
Vulnerability details
The vulnerability allows a remote user to access restricted administrative functionality.
The vulnerability exists due to improper access control in administrative functions when handling authenticated requests. A remote user can access administrative endpoints or features to access restricted administrative functionality.