PT-2026-21828 · Openemr · Openemr

Heshamm1

·

Published

2026-02-25

·

Updated

2026-03-02

·

CVE-2026-25131

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0
Description A Broken Access Control issue exists in the OpenEMR order types management system. Low-privilege users, such as Receptionists, can add and modify procedure types without proper authorization. This is due to insufficient access controls in the /openemr/interface/orders/types edit.php API endpoint. The vulnerability allows unauthorized manipulation of medical procedure types.
Recommendations Update to version 8.0.0 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25131
GHSA-6H2M-4PPF-PH4J

Affected Products

Openemr