Missing Authorization in OpenEMR - #VU149485
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive patient information.
The vulnerability exists due to missing authorization in the FHIR Media and QuestionnaireResponse read routes when handling requests for Media or QuestionnaireResponse resources. A remote user can send requests to unprotected FHIR read routes to disclose sensitive patient information.
Exploitation requires a non-patient API token with the relevant FHIR read scope but without the corresponding OpenEMR ACL.