PT-2026-26337 · Openemr · Openemr

Lassiiiiii

·

Published

2026-03-19

·

Updated

2026-03-23

·

CVE-2026-33321

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.2
Description OpenEMR is an electronic health records and medical practice management application. A Server-Side Request Forgery (SSRF) issue exists in the PDF creation function when processing form answers as unescaped HTML. This allows an attacker to forge requests from the server to external or internal resources. The issue affects users with the Notes - my encounters role who can fill Eye Exam forms in patient encounters. The vulnerability is triggered when the form answers are parsed as unescaped HTML during PDF creation. The vulnerable function is involved in processing form data for PDF generation.
Recommendations Update OpenEMR to version 8.0.0.2 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2026-05087
CVE-2026-33321
GHSA-5PC3-2CRW-96RV

Affected Products

Openemr