Openemr · Openemr · CVE-2026-32238
**Name of the Vulnerable Software and Affected Versions**
OpenEMR versions prior to 8.0.0.2
**Description**
OpenEMR is a free and open source electronic health records and medical practice management application. A command injection issue exists in the backup functionality due to insufficient input validation. This allows authenticated attackers to potentially compromise the system. The vulnerability allows for remote code execution.
**Recommendations**
Upgrade to version 8.0.0.2 to resolve the issue.