PT-2026-28143 · Openemr · Openemr

Published

2026-03-25

·

Updated

2026-03-26

·

CVE-2026-33913

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.3
Description OpenEMR is an electronic health records and medical practice management application. An authenticated user with access to the Carecoordination module can upload a specially crafted CCDA document to read arbitrary files from the server. The crafted document contains <xi:include href="file:///etc/passwd" parse="text"/>. The API endpoint used for uploading the document is not specified. The vulnerable parameter is the CCDA document itself.
Recommendations Update to version 8.0.0.3 or later.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2026-33913
GHSA-9757-3CFJ-WC8Q

Affected Products

Openemr