
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24487 is an authorization bypass vulnerability in OpenEMR's FHIR CareTeam resource endpoint that allows patient-scoped FHIR tokens to access care team data for all patients in the system, rather than being restricted to the authenticated patient's own data. It affects all OpenEMR versions prior to 8.0.0 and was disclosed on February 25, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (High) and a CVSS v4.0 base score of 5.7 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is an incomplete implementation of the patient compartment filtering mechanism, classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-863 (Incorrect Authorization). Specifically, FhirCareTeamService (in src/Services/FHIR/FhirCareTeamService.php) does not implement the IPatientCompartmentResourceService interface, so the ResourceServiceSearchTrait never injects the patient UUID filter into search queries. Additionally, the searchForOpenEMRRecords() method does not accept or forward the $puuidBind parameter to CareTeamService::getAll(), even though the underlying CareTeamService has the code to filter by patient UUID. An attacker with a valid patient-scoped FHIR OAuth2 token can send a simple unauthenticated-style GET request to /fhir/CareTeam and receive care team records for all patients in the system (GitHub Advisory).
Successful exploitation results in unauthorized disclosure of Protected Health Information (PHI) across the entire OpenEMR patient population, including patient-provider relationships, care team structures, and practitioner assignments. Any authenticated user with a low-privilege patient-scoped FHIR token can enumerate care team data for all patients without requiring privilege escalation. This exposure poses significant HIPAA compliance risk for healthcare organizations and could facilitate targeted social engineering or further attacks by revealing provider-patient relationships (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating the vulnerability with a simple curl command using a patient-scoped FHIR OAuth2 token. There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.038%, reflecting low but non-zero exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVSS v4.0 exploit maturity is rated as "Proof of Concept" (GitHub Advisory).
patient scope.curl -X GET "https://target-openemr.com/fhir/CareTeam" \
-H "Authorization: Bearer YOUR_PATIENT_SCOPED_TOKEN" \
-H "Accept: application/fhir+json"subject.reference fields exposing patient UUIDs and participant.member.reference fields exposing provider-patient relationships./fhir/CareTeam without a patient= query parameter from a single patient-scoped token; high-volume FHIR API requests from patient portal user accounts that would not normally query CareTeam data./fhir/CareTeam returning large FHIR Bundles (high total count) for patient-scoped tokens; OAuth2 token usage patterns where a single patient token queries CareTeam data repeatedly or in bulk./fhir/CareTeam containing subject.reference values pointing to multiple distinct patient UUIDs (indicating cross-patient data leakage rather than single-patient responses) (GitHub Advisory).The primary remediation is to upgrade OpenEMR to version 8.0.0 or later, which contains the patch (commit 5ce10a3) that corrects the FhirCareTeamService implementation (GitHub Patch). For organizations unable to upgrade immediately, the following interim controls are recommended: implement network-level access controls to restrict FHIR API endpoint access to authorized networks only; limit FHIR OAuth2 token scope assignments; and enhance monitoring and alerting on FHIR API access patterns, particularly for bulk CareTeam queries from patient-scoped tokens (GitHub Advisory).
Security Week reported on a broader set of 38 vulnerabilities found in OpenEMR medical software, of which CVE-2026-24487 was one, highlighting the systemic security concerns in widely-used healthcare software (Security Week). The vulnerability was discovered by researchers "simecek" (reporter) and "pavelkohout396" (analyst) and disclosed responsibly through GitHub's security advisory program. Aisle security researchers published a blog post detailing their discovery of 38 critical vulnerabilities in OpenEMR, used by over 100,000 healthcare providers (Aisle Blog). The Hacker News included coverage of these OpenEMR vulnerabilities in a weekly security recap (The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."