PT-2026-22100 · Openemr · Openemr
Simecek
·
Published
2026-02-26
·
Updated
2026-02-26
·
CVE-2026-27943
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions up to and including 8.0.0
Description
OpenEMR is an electronic health records and medical practice management application. Versions up to 8.0.0 do not verify that a form belongs to the current user’s patient or encounter context when loading data via the
form id parameter in the eye exam (eye mag) view. This allows an authenticated user to access or edit any patient’s eye exam by providing another form ID, and potentially switch the session’s active patient in some flows.Recommendations
Update to a version with the fix available on the
main branch of the OpenEMR GitHub repository.Exploit
Fix
LPE
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr