PT-2026-26346 · Openemr · Openemr

Pavelkohout396

+1

·

Published

2026-03-19

·

Updated

2026-03-23

·

CVE-2026-33304

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.2
Description OpenEMR is an electronic health records and medical practice management application. A flaw exists where an authenticated, non-administrator user can view reminder messages belonging to other users. This is achieved by manipulating the sentTo[] or sentBy[] parameters in a GET request to the dated reminders log. The issue allows access to patient names and the content of free-text messages.
Recommendations Update to OpenEMR version 8.0.0.2 or later.

Exploit

Fix

IDOR

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-05092
CVE-2026-33304
GHSA-66J9-FFQ4-H222

Affected Products

Openemr