PT-2026-22349 · Openemr · Openemr
Simecek
·
Published
2026-02-27
·
Updated
2026-02-27
·
CVE-2026-24488
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions up to and including 8.0.0
Description
OpenEMR is an electronic health records and medical practice management application. A flaw in the fax sending functionality allows any authenticated user to read and transmit any file on the server to a phone number controlled by an attacker. This is possible because the endpoint accepts arbitrary file paths from user input and streams them to the fax gateway without proper restrictions or authorization. The vulnerable endpoint is the fax sending endpoint. The issue allows access to files such as database credentials, patient documents, system files, and source code.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr