PT-2026-28158 · Openemr · Openemr
Published
2026-03-25
·
Updated
2026-03-26
·
CVE-2026-34056
CVSS v3.1
7.7
High
| AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 8.0.0.4
Description
OpenEMR is an electronic health records and medical practice management application. A Broken Access Control issue exists that allows users with limited privileges to view and download Ensora eRx error logs without authorization. This compromises the confidentiality of the system and could lead to unauthorized disclosure of sensitive information.
Recommendations
Update to a version later than 8.0.0.3.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openemr