PT-2026-28158 · Openemr · Openemr

Published

2026-03-25

·

Updated

2026-03-26

·

CVE-2026-34056

CVSS v3.1

7.7

High

AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.4
Description OpenEMR is an electronic health records and medical practice management application. A Broken Access Control issue exists that allows users with limited privileges to view and download Ensora eRx error logs without authorization. This compromises the confidentiality of the system and could lead to unauthorized disclosure of sensitive information.
Recommendations Update to a version later than 8.0.0.3.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-34056

Affected Products

Openemr