PT-2026-24844 · Git+1 · Openemr

Pavelkohout396

·

Published

2026-03-11

·

Updated

2026-03-11

·

CVE-2026-32123

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.1
Description OpenEMR is an electronic health records and medical practice management application. Prior to version 8.0.0.1, sensitivity checks for group encounters were not functioning correctly. The code was only checking the form encounter table for sensitivity information, while group encounters actually store this information in the form groups encounter table. This resulted in sensitivity restrictions not being applied to group encounters, potentially allowing unauthorized users to view sensitive information, such as mental health records.
Recommendations Upgrade to OpenEMR version 8.0.0.1 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32123
GHSA-J4MM-WG7Q-V57Q

Affected Products

Openemr