PT-2026-22349 · Openemr · Openemr

Simecek

·

Publicado

2026-02-27

·

Atualizado

2026-02-27

·

CVE-2026-24488

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions up to and including 8.0.0
Description OpenEMR is an electronic health records and medical practice management application. A flaw in the fax sending functionality allows any authenticated user to read and transmit any file on the server to a phone number controlled by an attacker. This is possible because the endpoint accepts arbitrary file paths from user input and streams them to the fax gateway without proper restrictions or authorization. The vulnerable endpoint is the fax sending endpoint. The issue allows access to files such as database credentials, patient documents, system files, and source code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24488
GHSA-765X-8V97-C7G8

Produtos afetados

Openemr