PT-2026-21824 · Openemr · Openemr

Tonghuaroot

·

Published

2026-02-25

·

Updated

2026-03-02

·

CVE-2026-24849

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 7.0.4
Description OpenEMR is an open source electronic health records and medical practice management application. Prior to version 7.0.4, the disposeDocument() method in EtherFaxActions.php allows authenticated users to read arbitrary files from the server filesystem. Any authenticated user, regardless of privilege level, can exploit this to read sensitive files. The disposeDocument() function is vulnerable.
Recommendations Update to version 7.0.4.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-24849
GHSA-W6VC-HX2X-48PC

Affected Products

Openemr