PT-2026-22836 · Openemr · Openemr
Firehed
·
Published
2026-03-03
·
Updated
2026-03-04
·
CVE-2026-25146
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions 5.0.2 through 8.0.0
Description
OpenEMR is an electronic health records and medical practice management application. Versions between 5.0.2 and before 8.0.0 have paths where the
gateway api key secret value is rendered to the client in plaintext. Exposure of these secret keys could lead to unauthorized money movement or account takeover of payment gateway APIs. The gateway api key is a sensitive variable used for accessing payment gateway APIs.Recommendations
Update to OpenEMR version 8.0.0.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr