PT-2026-28154 · Openemr · Openemr

Published

2026-03-25

·

Updated

2026-03-26

·

CVE-2026-33934

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.3
Description OpenEMR is an electronic health records and medical practice management application. A missing authorization check exists in portal/sign/lib/show-signature.php, allowing authenticated patient portal users to access the signature image of any staff member by manipulating the user parameter in the POST request. The save-signature.php endpoint was previously secured against this issue, but the show-signature.php endpoint remained vulnerable. The vulnerable parameter is user.
Recommendations Update to version 8.0.0.3 or later.

Exploit

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33934
GHSA-W9W5-7X6H-657Q

Affected Products

Openemr