CVE-2026-24487: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-24487 is an authorization bypass vulnerability in OpenEMR's FHIR CareTeam resource endpoint that allows patient-scoped FHIR tokens to access care team data for all patients in the system, rather than being restricted to the authenticated patient's own data. It affects all OpenEMR versions prior to 8.0.0 and was disclosed on February 25, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (High) and a CVSS v4.0 base score of 5.7 (Medium) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is an incomplete implementation of the patient compartment filtering mechanism, classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-863 (Incorrect Authorization). Specifically, FhirCareTeamService (in src/Services/FHIR/FhirCareTeamService.php) does not implement the IPatientCompartmentResourceService interface, so the ResourceServiceSearchTrait never injects the patient UUID filter into search queries. Additionally, the searchForOpenEMRRecords() method does not accept or forward the $puuidBind parameter to CareTeamService::getAll(), even though the underlying CareTeamService has the code to filter by patient UUID. An attacker with a valid patient-scoped FHIR OAuth2 token can send a simple unauthenticated-style GET request to /fhir/CareTeam and receive care team records for all patients in the system (GitHub Advisory).

Impact

Successful exploitation results in unauthorized disclosure of Protected Health Information (PHI) across the entire OpenEMR patient population, including patient-provider relationships, care team structures, and practitioner assignments. Any authenticated user with a low-privilege patient-scoped FHIR token can enumerate care team data for all patients without requiring privilege escalation. This exposure poses significant HIPAA compliance risk for healthcare organizations and could facilitate targeted social engineering or further attacks by revealing provider-patient relationships (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating the vulnerability with a simple curl command using a patient-scoped FHIR OAuth2 token. There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.038%, reflecting low but non-zero exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVSS v4.0 exploit maturity is rated as "Proof of Concept" (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing OpenEMR instances with FHIR API enabled (versions prior to 8.0.0) using tools like Shodan or Censys, searching for OpenEMR patient portals or SMART on FHIR endpoints.
  2. Obtain a patient-scoped FHIR token: Register or log in as a patient via the OpenEMR patient portal and complete the standard OAuth2/SMART on FHIR authentication flow to obtain a patient-scoped bearer token with patient scope.
  3. Send unauthenticated-style CareTeam request: Issue a GET request to the FHIR CareTeam endpoint without specifying a patient filter parameter:
curl -X GET "https://target-openemr.com/fhir/CareTeam" \
  -H "Authorization: Bearer YOUR_PATIENT_SCOPED_TOKEN" \
  -H "Accept: application/fhir+json"
  1. Harvest PHI: The response returns a FHIR Bundle containing care team records for all patients in the system, including subject.reference fields exposing patient UUIDs and participant.member.reference fields exposing provider-patient relationships.
  2. Enumerate further: Cross-reference exposed patient UUIDs and practitioner references with other FHIR endpoints to build a comprehensive picture of the patient population and provider assignments (GitHub Advisory).

Indicators of compromise

  • Network: Repeated GET requests to /fhir/CareTeam without a patient= query parameter from a single patient-scoped token; high-volume FHIR API requests from patient portal user accounts that would not normally query CareTeam data.
  • Logs: OpenEMR access logs showing requests to /fhir/CareTeam returning large FHIR Bundles (high total count) for patient-scoped tokens; OAuth2 token usage patterns where a single patient token queries CareTeam data repeatedly or in bulk.
  • Application Behavior: FHIR Bundle responses to /fhir/CareTeam containing subject.reference values pointing to multiple distinct patient UUIDs (indicating cross-patient data leakage rather than single-patient responses) (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade OpenEMR to version 8.0.0 or later, which contains the patch (commit 5ce10a3) that corrects the FhirCareTeamService implementation (GitHub Patch). For organizations unable to upgrade immediately, the following interim controls are recommended: implement network-level access controls to restrict FHIR API endpoint access to authorized networks only; limit FHIR OAuth2 token scope assignments; and enhance monitoring and alerting on FHIR API access patterns, particularly for bulk CareTeam queries from patient-scoped tokens (GitHub Advisory).

Community reactions

Security Week reported on a broader set of 38 vulnerabilities found in OpenEMR medical software, of which CVE-2026-24487 was one, highlighting the systemic security concerns in widely-used healthcare software (Security Week). The vulnerability was discovered by researchers "simecek" (reporter) and "pavelkohout396" (analyst) and disclosed responsibly through GitHub's security advisory program. Aisle security researchers published a blog post detailing their discovery of 38 critical vulnerabilities in OpenEMR, used by over 100,000 healthcare providers (Aisle Blog). The Hacker News included coverage of these OpenEMR vulnerabilities in a weekly security recap (The Hacker News).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management