
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67645 is a broken access control vulnerability in the OpenEMR patient portal's Profile Edit endpoint, classified as an Insecure Direct Object Reference (IDOR). An authenticated normal user can manipulate the pid and pubpid request parameters to reference and overwrite another user's patient record. The vulnerability affects OpenEMR versions prior to 7.0.4 (specifically confirmed in 7.0.3), and was published on January 27–28, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Red Hat CVE).
The root cause is CWE-284 (Improper Access Control) in portal/patient/libs/Controller/PatientController.php. The vulnerable Update() method accepted user-supplied pid and pubpid values directly from the request JSON and applied them to the database without verifying that the authenticated session's $_SESSION['pid'] matched the target patient record. The fix adds an explicit authorization check comparing $_SESSION['pid'] to the patient record's Pid field before processing any updates, and removes pid/pubpid from the set of user-modifiable fields entirely (GitHub Commit, GitHub Advisory).
Successful exploitation allows any authenticated portal user to persistently overwrite another patient's profile data — including name, contact information, and HIPAA consent fields — without the victim's knowledge. In a healthcare context, this creates serious data integrity risks for electronic health records. If email or username fields are editable, the attack can escalate to a full account takeover (ATO), and if an administrator commits the attacker-submitted changes to the patient chart, the corrupted data becomes part of the official medical record (GitHub Advisory).
A proof-of-concept (PoC) is publicly documented in the official GitHub Security Advisory, detailing a step-by-step exploitation scenario using request interception. No evidence of in-the-wild exploitation or threat actor attribution has been reported at this time. The EPSS score is approximately 0.039% (low probability of near-term exploitation), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).
pid field to the target victim's patient ID and pubpid to the victim's public patient identifier (e.g., {"pid": 10, "pubpid": "user-b-pub-id", "fname": "Modified", "email": "attacker@example.com"})./portal/patient/...) where the pid or pubpid values in the request body differ from the authenticated session's patient ID.$_SESSION['pid']) does not match the pid parameter submitted in the profile update request body (GitHub Advisory).Upgrade all OpenEMR installations to version 7.0.4 or later, which adds an authorization check in PatientController.php to ensure $_SESSION['pid'] matches the target patient record before processing any update, and removes pid/pubpid from user-modifiable fields. As a temporary measure prior to upgrading, administrators should consider restricting access to the patient portal Profile Edit endpoint or disabling it entirely. Additionally, review portal audit logs for suspicious cross-account profile modifications that may have occurred before patching (GitHub Commit, GitHub Advisory).
The vulnerability was reported by security researcher mayankprajapat01 and published by the OpenEMR maintainers via GitHub Security Advisory on January 27, 2026. Coverage appeared on security aggregation sites including The Hacker Wire and ctrlaltnod.com shortly after disclosure. No major vendor statements beyond the official advisory or significant social media debate have been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."