PT-2026-21816 · Openemr · Openemr

Published

2026-02-25

·

Updated

2026-03-02

·

CVE-2025-67752

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 7.0.4
Description OpenEMR’s HTTP client wrapper (oeHttp/oeHttpRequest) has a default setting that disables SSL/TLS certificate verification (verify: false). This makes all external HTTPS connections susceptible to man-in-the-middle (MITM) attacks. This impacts communication with government healthcare APIs and user-configurable external services, potentially exposing Protected Health Information (PHI).
Recommendations Update to version 7.0.4 or later.

Exploit

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-67752
GHSA-2G6H-725P-PQHP

Affected Products

Openemr