PT-2026-22834 · Openemr · Openemr

Tonghuaroot

·

Published

2026-03-03

·

Updated

2026-03-04

·

CVE-2026-24848

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 7.0.5
Description OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.5 contain a flaw in the disposeDocument() method within the EtherFaxActions.php file. This allows authenticated users to write arbitrary content to arbitrary locations on the server filesystem, potentially leading to Remote Code Execution (RCE) through the upload of malicious PHP web shells. The vulnerable method allows for the writing of files to the server.
Recommendations Update OpenEMR to version 7.0.5 or later.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-24848
GHSA-5VP5-4RM6-H4C9

Affected Products

Openemr