PT-2026-28158 · Openemr · Openemr

Published

2026-03-25

·

Updated

2026-03-26

·

CVE-2026-34056

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.4
Description OpenEMR is an electronic health records and medical practice management application. A Broken Access Control issue exists that allows users with limited privileges to view and download Ensora eRx error logs without authorization. This compromises the confidentiality of the system and could lead to unauthorized disclosure of sensitive information.
Recommendations Update to a version later than 8.0.0.3.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-34056
GHSA-6QG7-6JF3-XRFH

Affected Products

Openemr