Authorization bypass through user-controlled key in OpenEMR - #VU149486

 

Authorization bypass through user-controlled key in OpenEMR - #VU149486

Published: September 14, 2026


Vulnerability identifier: #VU149486
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive patient information.

The vulnerability exists due to improper access control in the SMART on FHIR patient binding validation method when processing SMART launch context mapping. A remote user can specify an arbitrary patient UUID in the token context to disclose sensitive patient information.

The validation method unconditionally returns true without verifying the requesting user's relationship to the patient.


Affected software

OpenEMR

Remediation

Install security update from vendor's website.

OpenEMR - update to 8.4.0

External References

Related Security Bulletins