PT-2026-24844 · Git+1 · Openemr

·

CVE-2026-32123

·

Published

2026-03-11

·

Updated

2026-03-11

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.1
Description OpenEMR is an electronic health records and medical practice management application. Prior to version 8.0.0.1, sensitivity checks for group encounters were not functioning correctly. The code was only checking the form encounter table for sensitivity information, while group encounters actually store this information in the form groups encounter table. This resulted in sensitivity restrictions not being applied to group encounters, potentially allowing unauthorized users to view sensitive information, such as mental health records.
Recommendations Upgrade to OpenEMR version 8.0.0.1 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32123
GHSA-J4MM-WG7Q-V57Q

Affected Products

Openemr