PT-2026-24841 · Git+1 · Openemr

Pavelkohout396

·

Published

2026-03-11

·

Updated

2026-03-11

·

CVE-2026-32122

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.1
Description OpenEMR is an electronic health records and medical practice management application. The Claim File Tracker feature exposes an AJAX endpoint that returns billing claim metadata, including claim IDs, payer information, and transmission logs. This endpoint does not enforce the same Access Control List (ACL) as the main billing/claims workflow, allowing authenticated users without appropriate billing permissions to access sensitive data. The vulnerable API endpoint is an AJAX endpoint used by the Claim File Tracker feature. The issue arises because the endpoint does not properly validate user permissions before returning billing claim metadata. The vulnerable parameter is not explicitly mentioned.
Recommendations Update OpenEMR to version 8.0.0.1 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32122
GHSA-RWF9-PX3C-3PRW

Affected Products

Openemr