
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24896 is a Broken Access Control vulnerability in OpenEMR's edih_main.php endpoint that allows any authenticated user — including low-privilege roles such as Receptionist — to access sensitive EDI log files by manipulating the log_select parameter in a crafted GET request. It affects all OpenEMR versions prior to 8.0.0 and was disclosed on February 25, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Feedly).
The root cause is CWE-284 (Improper Access Control): the edih_main.php AJAX endpoint validates only a CSRF token but performs no role-based access control (RBAC) check before invoking edih_disp_log(), which reads and returns EDI log file contents via csv_log_html(). The parent page edih_view.php enforces ACL checks through OpenEMR's AclMain::aclCheckCore('acct', 'eob'), but the backend AJAX endpoint was missing this guard, allowing direct access that bypasses the GUI-enforced permission boundary. The vulnerable code paths are in interface/billing/edih_main.php (lines 180–200) and library/edihistory/edih_io.php (lines 30–40). A public proof-of-concept request is included in the GitHub security advisory (GitHub Advisory, Patch Commit).
Successful exploitation allows an authenticated low-privilege user to read the contents of EDI (Electronic Data Interchange) log files that should be restricted to higher-privilege roles. These logs may contain Protected Health Information (PHI), system metadata, and transaction control numbers, enabling unauthorized disclosure of sensitive healthcare data. Secondary risks include using exposed log data to facilitate further attacks such as control number spoofing and bypassing audit controls (GitHub Advisory). There is no integrity or availability impact; the confidentiality impact is rated High.
A proof-of-concept exploit is publicly available in the GitHub security advisory, demonstrating exploitation via a simple crafted GET request requiring only a valid low-privilege session cookie (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.028% (very low probability of exploitation in the near term) (Feedly). This CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
OpenEMR=<session_id>) from the browser or an intercepting proxy such as Burp Suite.edih_log_YYYY-MM-DD.txt). Enumerate possible filenames by guessing dates or observing application behavior.GET /openemr/interface/billing/edih_main.php?csrf_token_form=<valid_csrf>&log_select=edih_log_2025-04-20.txt&logshowfile=getlog HTTP/1.1
Host: <target>
Cookie: OpenEMR=<session_id>
X-Requested-With: XMLHttpRequest/openemr/interface/billing/edih_main.php with log_select and logshowfile=getlog parameters originating from accounts with low-privilege roles (e.g., Receptionist).edih_main.php?log_select=edih_log_*.txt from user sessions not associated with billing or administrative roles; HTTP 200 responses to these requests indicating successful log retrieval.acct/eob ACL permissions.edih_main.php with varying date-based log_select values, suggesting enumeration of available log files (GitHub Advisory).Upgrade OpenEMR to version 8.0.0 or later, which adds the missing AclMain::aclCheckCore('acct', 'eob') check at the entry point of edih_main.php, matching the access control already enforced by edih_view.php (Patch Commit). For systems unable to upgrade immediately, restrict network-level access to the OpenEMR application to authorized personnel only, and minimize the number of active low-privilege user accounts. Additionally, review web server and application logs for unauthorized access to edih_main.php and consider implementing a WAF rule to block requests to this endpoint from non-administrative sessions (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."