Insufficient Session Expiration in OpenEMR - #VU149482
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive patient information and perform patient-facing actions.
The vulnerability exists due to failure to enforce one-time token-use restrictions in the OneTimeAuth token-consumption path in src/Common/Auth/OneTimeAuth.php when submitting a captured service_auth token to the patient portal. A remote attacker can replay a valid token to disclose sensitive patient information and perform patient-facing actions.
For PIN-protected flows, exploitation also requires the associated PIN.