CVE-2025-67645: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2025-67645 is a broken access control vulnerability in the OpenEMR patient portal's Profile Edit endpoint, classified as an Insecure Direct Object Reference (IDOR). An authenticated normal user can manipulate the pid and pubpid request parameters to reference and overwrite another user's patient record. The vulnerability affects OpenEMR versions prior to 7.0.4 (specifically confirmed in 7.0.3), and was published on January 27–28, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is CWE-284 (Improper Access Control) in portal/patient/libs/Controller/PatientController.php. The vulnerable Update() method accepted user-supplied pid and pubpid values directly from the request JSON and applied them to the database without verifying that the authenticated session's $_SESSION['pid'] matched the target patient record. The fix adds an explicit authorization check comparing $_SESSION['pid'] to the patient record's Pid field before processing any updates, and removes pid/pubpid from the set of user-modifiable fields entirely (GitHub Commit, GitHub Advisory).

Impact

Successful exploitation allows any authenticated portal user to persistently overwrite another patient's profile data — including name, contact information, and HIPAA consent fields — without the victim's knowledge. In a healthcare context, this creates serious data integrity risks for electronic health records. If email or username fields are editable, the attack can escalate to a full account takeover (ATO), and if an administrator commits the attacker-submitted changes to the patient chart, the corrupted data becomes part of the official medical record (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) is publicly documented in the official GitHub Security Advisory, detailing a step-by-step exploitation scenario using request interception. No evidence of in-the-wild exploitation or threat actor attribution has been reported at this time. The EPSS score is approximately 0.039% (low probability of near-term exploitation), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Authenticate: Log in to the OpenEMR patient portal as any valid normal user (e.g., User A / Phil Belford) and capture the session cookies.
  2. Navigate to Profile Edit: Go to Dashboard → Profile and click the "Edit Profile" button to load the profile update form.
  3. Intercept the request: Use a proxy tool (e.g., Burp Suite) to intercept the HTTP request generated when submitting a profile update.
  4. Manipulate parameters: In the intercepted request body (JSON), change the pid field to the target victim's patient ID and pubpid to the victim's public patient identifier (e.g., {"pid": 10, "pubpid": "user-b-pub-id", "fname": "Modified", "email": "attacker@example.com"}).
  5. Forward the request: Send the modified request to the server. The server applies the changes to the victim's (User B / Susan's) profile record without authorization checks.
  6. Verify impact: Visit the victim's profile in the portal — the attacker's changes are now reflected. In the Admin Portal → Portal Audits → Onsite Patient Activities, the admin can see the changes and, if committed, they become part of the official chart, potentially enabling account takeover (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST/PUT requests to the patient portal profile update endpoint (e.g., /portal/patient/...) where the pid or pubpid values in the request body differ from the authenticated session's patient ID.
  • Logs: OpenEMR portal audit logs (Admin Portal → Portal Audits → Onsite Patient Activities) showing profile modification events attributed to a user account that does not match the modified patient's record.
  • Application Behavior: Multiple patient profiles showing unexpected changes to name, contact information, email, or HIPAA consent fields without corresponding patient-initiated activity.
  • Session Analysis: Requests where the session-bound patient ID ($_SESSION['pid']) does not match the pid parameter submitted in the profile update request body (GitHub Advisory).

Mitigation and workarounds

Upgrade all OpenEMR installations to version 7.0.4 or later, which adds an authorization check in PatientController.php to ensure $_SESSION['pid'] matches the target patient record before processing any update, and removes pid/pubpid from user-modifiable fields. As a temporary measure prior to upgrading, administrators should consider restricting access to the patient portal Profile Edit endpoint or disabling it entirely. Additionally, review portal audit logs for suspicious cross-account profile modifications that may have occurred before patching (GitHub Commit, GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher mayankprajapat01 and published by the OpenEMR maintainers via GitHub Security Advisory on January 27, 2026. Coverage appeared on security aggregation sites including The Hacker Wire and ctrlaltnod.com shortly after disclosure. No major vendor statements beyond the official advisory or significant social media debate have been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management