PT-2026-24844 · Git+1 · Openemr
Pavelkohout396
·
Published
2026-03-11
·
Updated
2026-03-11
·
CVE-2026-32123
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 8.0.0.1
Description
OpenEMR is an electronic health records and medical practice management application. Prior to version 8.0.0.1, sensitivity checks for group encounters were not functioning correctly. The code was only checking the
form encounter table for sensitivity information, while group encounters actually store this information in the form groups encounter table. This resulted in sensitivity restrictions not being applied to group encounters, potentially allowing unauthorized users to view sensitive information, such as mental health records.Recommendations
Upgrade to OpenEMR version 8.0.0.1 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr