Home

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not properly validate user permission. Unauthorized users can view the information of authorized users. Version 8.0.0 fixes the issue.

PUBLISHED Reserved 2026-01-29 | Published 2026-02-25 | Updated 2026-02-25 | Assigner GitHub_M




HIGH: 7.0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Problem types

CWE-863: Incorrect Authorization

Product status

< 8.0.0
affected

References

github.com/...penemr/security/advisories/GHSA-69cv-rv28-4g85

github.com/...ommit/ad902d6892482fff2e3c56bfb15597df8b6c3beb

cve.org (CVE-2026-25127)

nvd.nist.gov (CVE-2026-25127)

Download JSON