CVE-2025-54373: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2025-54373 is a sensitive data exposure vulnerability in OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. In versions prior to 7.0.4, the application fails to properly enforce sensitivity-based access controls, allowing users with only Sensitivities=Normal privilege to view and modify Clinical Notes and Care Plan contents belonging to encounters marked Sensitivity=high. The vulnerability was published on January 27–28, 2026, and patched in OpenEMR version 7.0.4. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerability exists in interface/patient_file/encounterforms.php, where the application correctly hides encounter details from low-privilege users but fails to restrict access to specific form types — specifically Clinical Notes and Care Plan — when those forms are opened directly from the encounter menu. A low-privileged authenticated user (e.g., a Clinician with Sensitivities=Normal) can trigger a pop-up for an existing Clinical Notes or Care Plan form tied to a high-sensitivity encounter, which then reveals the protected content. The fix, committed in aef3d1c, enforces a check that hides these menus when the user's sensitivity permission is lower than the encounter's sensitivity level (GitHub Advisory, GitHub Commit).

Impact

Successful exploitation allows authenticated low-privileged users to read and modify Protected Health Information (PHI) contained in Clinical Notes and Care Plan forms for high-sensitivity patient encounters — data they are explicitly not authorized to access. This constitutes a breach of patient privacy and medical record integrity, with potential regulatory consequences under HIPAA and similar frameworks. Notably, the bypass is limited to Clinical Notes and Care Plan forms; other form types such as SOAP Notes, Treatment Plans, and Clinical Instructions are not affected by this specific flaw (GitHub Advisory).

Exploitability

A proof-of-concept is publicly documented in the GitHub Security Advisory, which provides detailed reproduction steps. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042%, reflecting low but non-zero probability of exploitation in the near term (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Obtain low-privileged credentials: Acquire valid OpenEMR credentials for a user account with Sensitivities=Normal (e.g., a Clinician role), which can be a standard staff account without elevated sensitivity permissions.
  2. Identify a high-sensitivity encounter: Log in and observe the encounter drop-down in the page banner area. Even low-privileged users can see that a high-sensitivity encounter exists in the list, though the encounter details display "Not authorized to view this encounter."
  3. Navigate to the encounter menu: While viewing the restricted encounter, access the encounter forms menu. The application does not fully suppress Clinical Notes and Care Plan menu options for low-privileged users.
  4. Open Clinical Notes or Care Plan form: Select "Clinical Notes" or "Care Plan" from the encounter menu. A pop-up appears stating "Already a Clinical Notes form for this encounter. Using existing Clinical Notes form."
  5. Access restricted PHI: The existing form content — entered by a high-privilege user for the high-sensitivity encounter — is now fully visible and editable by the low-privileged user, exposing the protected clinical data (GitHub Advisory).

Indicators of compromise

  • Logs: OpenEMR application logs showing low-privileged user accounts (with Sensitivities=Normal ACL) accessing encounterforms.php for encounters they are not authorized to view; repeated access to Clinical Notes or Care Plan form endpoints by users whose role does not include Sensitivities=high.
  • Application Audit Trail: OpenEMR's built-in audit log entries showing form opens or edits on high-sensitivity encounters by users with insufficient sensitivity privileges — particularly for Clinical Notes and Care Plan form types.
  • Database: Unexpected modification timestamps on form_clinical_notes or form_care_plan records associated with high-sensitivity encounters, where the modifying user account lacks Sensitivities=high privilege.

Mitigation and workarounds

Upgrade OpenEMR to version 7.0.4 or later, which contains the fix applied in commit aef3d1c that enforces sensitivity-level checks before rendering Clinical Notes and Care Plan menu options (GitHub Commit, GitHub Advisory). If immediate patching is not feasible, implement network-level controls to restrict OpenEMR access to only authorized clinical staff, and audit existing user ACL assignments to ensure Sensitivities=high is granted only to appropriate personnel. Additionally, review OpenEMR audit logs for any unauthorized access to high-sensitivity encounter forms that may have occurred prior to patching.

Community reactions

The vulnerability was published by OpenEMR maintainer bradymiller via a GitHub Security Advisory on January 27, 2026, with credit to sjpadgett for the remediation. Red Hat also tracked the CVE through their security advisory system. No significant broader media coverage or notable independent researcher commentary has been identified beyond the official advisory and standard vulnerability database aggregators (GitHub Advisory, Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management