CVE-2026-24908: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-24908 is an SQL injection vulnerability in OpenEMR's Patient REST API endpoint that allows authenticated users with API access to execute arbitrary SQL queries via the _sort parameter. It affects all OpenEMR versions prior to 8.0.0 and was disclosed on February 25, 2026, by researchers simecek and pavelkohout396 via a GitHub Security Advisory. The NVD assigns a CVSS v3.1 base score of 6.5 (Medium), while the GitHub Security Advisory rates it 9.9 (Critical) with a changed scope reflecting broader impact potential (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is CWE-89 (SQL Injection): user-supplied sort field names from the _sort query parameter are passed directly into SQL ORDER BY clauses without input validation, whitelisting, or identifier escaping. The vulnerable code path flows through apis/routes/_rest_routes_standard.inc.php (line 786) → SearchQueryConfig::createConfigFromQueryParams() (src/Services/Search/SearchQueryConfig.php, lines 71–80) → SearchConfigClauseBuilder::buildSortOrderClauseFromConfig() (src/Services/Search/SearchConfigClauseBuilder.php, lines 27–30), where field names are concatenated directly into the ORDER BY string. Notably, the codebase already contained an escaping function (QueryUtils::escapeColumnName()) used elsewhere, but it was not applied here. The fix introduced a strict column whitelist (ALLOWED_SORT_COLUMNS) in PatientService.php and updated buildSortOrderClauseFromConfig() to reject any field not on the whitelist (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows authenticated API users to execute arbitrary SQL queries against the OpenEMR database, exposing Protected Health Information (PHI) such as patient demographics, medical records, and contact details. Attackers can also extract credential data (e.g., usernames and password hashes from the users table), and potentially modify or delete database records. Given that OpenEMR is used by healthcare organizations managing sensitive patient data, a breach could result in HIPAA violations, regulatory penalties, and significant harm to patient privacy (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating both time-based blind SQL injection (using SLEEP(5)) and data extraction techniques. Exploitation requires a valid OAuth2 bearer token (low-privilege authenticated access) but no user interaction, and is executable remotely over the network. The EPSS score is approximately 0.03%, indicating currently low predicted exploitation probability. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Obtain API credentials: Authenticate to the target OpenEMR instance via the standard OAuth2 flow to obtain a valid bearer token (requires a low-privilege account with API access enabled).
  2. Identify the vulnerable endpoint: Confirm the target is running OpenEMR prior to version 8.0.0 with the REST API enabled at /apis/api/patient.
  3. Confirm injection with time-based test: Send a crafted GET request with a malicious _sort parameter to confirm SQL injection:
    curl -X GET "https://target-openemr.com/apis/api/patient?_sort=uuid,(SELECT SLEEP(5))--" \
      -H "Authorization: Bearer YOUR_ACCESS_TOKEN"
    A ~5-second response delay confirms the injected SQL is executing.
  4. Extract sensitive data: Use a subquery in the _sort parameter to exfiltrate data from arbitrary tables:
    curl -X GET "https://target-openemr.com/apis/api/patient?_sort=uuid,(SELECT username FROM users WHERE id=1 LIMIT 1)--" \
      -H "Authorization: Bearer YOUR_ACCESS_TOKEN"
  5. Enumerate and exfiltrate PHI/credentials: Iterate over database tables (e.g., patient_data, users) to extract PHI records, password hashes, and other sensitive data using blind or error-based SQL injection techniques (GitHub Advisory).

Indicators of compromise

  • Network: Unusual GET requests to /apis/api/patient with _sort parameter values containing SQL syntax (e.g., SELECT, SLEEP, --, parentheses, or subqueries); repeated API calls with varying _sort payloads from a single source IP.
  • Logs: OpenEMR API access logs showing requests to /apis/api/patient?_sort= with encoded or plaintext SQL fragments; database slow query logs showing ORDER BY clauses containing subqueries or SQL functions (e.g., SLEEP()).
  • Application Behavior: Abnormally slow API responses (5+ seconds) to patient list endpoints, consistent with time-based blind SQL injection probing.
  • Database: Unexpected queries in the database audit log originating from the OpenEMR application user that include ORDER BY (SELECT ...) patterns or reference tables outside normal patient data operations (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0 or later, which resolves the vulnerability by implementing a strict column whitelist (ALLOWED_SORT_COLUMNS) and rejecting any _sort values not on the approved list (Patch Commit). For organizations unable to patch immediately, restrict REST API access to trusted, authorized users only and implement network-level controls (e.g., firewall rules, API gateway policies) to limit exposure of the /apis/api/patient endpoint. Additionally, monitor API logs for _sort parameter values containing SQL-like syntax as a detection measure (GitHub Advisory).

Community reactions

The vulnerability was part of a broader batch of 38 security flaws discovered in OpenEMR, which received coverage from multiple healthcare and cybersecurity media outlets including BankInfoSecurity, HealthcareInfoSecurity, DataBreachToday, SecurityWeek, and The Hacker News (BankInfoSecurity, SecurityWeek). The discovery was attributed to security researchers at Aisle, who published a blog post highlighting the critical nature of the findings in healthcare software used by over 100,000 providers (Aisle Blog). The Hacker News also referenced the OpenEMR flaws in its weekly threat recap bulletins, indicating notable community attention to the healthcare software security implications.

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management