PT-2026-28154 · Openemr · Openemr

Published

2026-03-25

·

Updated

2026-03-26

·

CVE-2026-33934

CVSS v3.1

4.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.3
Description OpenEMR is an electronic health records and medical practice management application. A missing authorization check exists in portal/sign/lib/show-signature.php, allowing authenticated patient portal users to access the signature image of any staff member by manipulating the user parameter in the POST request. The save-signature.php endpoint was previously secured against this issue, but the show-signature.php endpoint remained vulnerable. The vulnerable parameter is user.
Recommendations Update to version 8.0.0.3 or later.

Fix

IDOR

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-33934

Affected Products

Openemr