PT-2026-21975 · Openemr · Openemr

Simecek

·

Publicado

2026-02-25

·

Atualizado

2026-02-27

·

CVE-2026-25164

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0
Description OpenEMR is an electronic health records and medical practice management application. Prior to version 8.0.0, the REST API route table in apis/routes/ rest routes standard.inc.php does not call RestConfig::request authorization check() for document and insurance routes. This allows any valid API bearer token to access or modify patient documents and insurance data, regardless of assigned permissions, potentially exposing Protected Health Information (PHI). The vulnerable routes do not perform appropriate access control verification. The RestConfig::request authorization check() function is not invoked for specific API endpoints.
Recommendations Versions prior to 8.0.0 should be updated to version 8.0.0 or later.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25164
GHSA-F64C-H2GH-G3F9

Produtos afetados

Openemr