CVE-2026-24896: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-24896 is a Broken Access Control vulnerability in OpenEMR's edih_main.php endpoint that allows any authenticated user — including low-privilege roles such as Receptionist — to access sensitive EDI log files by manipulating the log_select parameter in a crafted GET request. It affects all OpenEMR versions prior to 8.0.0 and was disclosed on February 25, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-284 (Improper Access Control): the edih_main.php AJAX endpoint validates only a CSRF token but performs no role-based access control (RBAC) check before invoking edih_disp_log(), which reads and returns EDI log file contents via csv_log_html(). The parent page edih_view.php enforces ACL checks through OpenEMR's AclMain::aclCheckCore('acct', 'eob'), but the backend AJAX endpoint was missing this guard, allowing direct access that bypasses the GUI-enforced permission boundary. The vulnerable code paths are in interface/billing/edih_main.php (lines 180–200) and library/edihistory/edih_io.php (lines 30–40). A public proof-of-concept request is included in the GitHub security advisory (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated low-privilege user to read the contents of EDI (Electronic Data Interchange) log files that should be restricted to higher-privilege roles. These logs may contain Protected Health Information (PHI), system metadata, and transaction control numbers, enabling unauthorized disclosure of sensitive healthcare data. Secondary risks include using exposed log data to facilitate further attacks such as control number spoofing and bypassing audit controls (GitHub Advisory). There is no integrity or availability impact; the confidentiality impact is rated High.

Exploitability

A proof-of-concept exploit is publicly available in the GitHub security advisory, demonstrating exploitation via a simple crafted GET request requiring only a valid low-privilege session cookie (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.028% (very low probability of exploitation in the near term) (Feedly). This CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Obtain low-privilege credentials: Log in to the target OpenEMR instance using any valid account, including a Receptionist-level role that does not have GUI access to EDI logs.
  2. Capture a valid session token: After login, retrieve the active session cookie (e.g., OpenEMR=<session_id>) from the browser or an intercepting proxy such as Burp Suite.
  3. Identify a log file name: EDI log files follow a predictable naming convention (e.g., edih_log_YYYY-MM-DD.txt). Enumerate possible filenames by guessing dates or observing application behavior.
  4. Craft the malicious GET request: Send a direct HTTP GET request to the vulnerable endpoint, bypassing the GUI:
GET /openemr/interface/billing/edih_main.php?csrf_token_form=<valid_csrf>&log_select=edih_log_2025-04-20.txt&logshowfile=getlog HTTP/1.1
Host: <target>
Cookie: OpenEMR=<session_id>
X-Requested-With: XMLHttpRequest
  1. Retrieve log contents: The server returns the full contents of the specified EDI log file in the HTTP response, exposing PHI and system metadata without any permission check (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP GET requests to /openemr/interface/billing/edih_main.php with log_select and logshowfile=getlog parameters originating from accounts with low-privilege roles (e.g., Receptionist).
  • Logs: Web server access logs showing requests to edih_main.php?log_select=edih_log_*.txt from user sessions not associated with billing or administrative roles; HTTP 200 responses to these requests indicating successful log retrieval.
  • Application Logs: OpenEMR audit logs showing EDI log access events for user accounts that do not have acct/eob ACL permissions.
  • Behavioral: Repeated or automated requests to edih_main.php with varying date-based log_select values, suggesting enumeration of available log files (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0 or later, which adds the missing AclMain::aclCheckCore('acct', 'eob') check at the entry point of edih_main.php, matching the access control already enforced by edih_view.php (Patch Commit). For systems unable to upgrade immediately, restrict network-level access to the OpenEMR application to authorized personnel only, and minimize the number of active low-privilege user accounts. Additionally, review web server and application logs for unauthorized access to edih_main.php and consider implementing a WAF rule to block requests to this endpoint from non-administrative sessions (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management