
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24908 is an SQL injection vulnerability in OpenEMR's Patient REST API endpoint that allows authenticated users with API access to execute arbitrary SQL queries via the _sort parameter. It affects all OpenEMR versions prior to 8.0.0 and was disclosed on February 25, 2026, by researchers simecek and pavelkohout396 via a GitHub Security Advisory. The NVD assigns a CVSS v3.1 base score of 6.5 (Medium), while the GitHub Security Advisory rates it 9.9 (Critical) with a changed scope reflecting broader impact potential (GitHub Advisory, Red Hat CVE).
The root cause is CWE-89 (SQL Injection): user-supplied sort field names from the _sort query parameter are passed directly into SQL ORDER BY clauses without input validation, whitelisting, or identifier escaping. The vulnerable code path flows through apis/routes/_rest_routes_standard.inc.php (line 786) → SearchQueryConfig::createConfigFromQueryParams() (src/Services/Search/SearchQueryConfig.php, lines 71–80) → SearchConfigClauseBuilder::buildSortOrderClauseFromConfig() (src/Services/Search/SearchConfigClauseBuilder.php, lines 27–30), where field names are concatenated directly into the ORDER BY string. Notably, the codebase already contained an escaping function (QueryUtils::escapeColumnName()) used elsewhere, but it was not applied here. The fix introduced a strict column whitelist (ALLOWED_SORT_COLUMNS) in PatientService.php and updated buildSortOrderClauseFromConfig() to reject any field not on the whitelist (GitHub Advisory, Patch Commit).
Successful exploitation allows authenticated API users to execute arbitrary SQL queries against the OpenEMR database, exposing Protected Health Information (PHI) such as patient demographics, medical records, and contact details. Attackers can also extract credential data (e.g., usernames and password hashes from the users table), and potentially modify or delete database records. Given that OpenEMR is used by healthcare organizations managing sensitive patient data, a breach could result in HIPAA violations, regulatory penalties, and significant harm to patient privacy (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating both time-based blind SQL injection (using SLEEP(5)) and data extraction techniques. Exploitation requires a valid OAuth2 bearer token (low-privilege authenticated access) but no user interaction, and is executable remotely over the network. The EPSS score is approximately 0.03%, indicating currently low predicted exploitation probability. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (GitHub Advisory, Red Hat CVE).
/apis/api/patient._sort parameter to confirm SQL injection:curl -X GET "https://target-openemr.com/apis/api/patient?_sort=uuid,(SELECT SLEEP(5))--" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"A ~5-second response delay confirms the injected SQL is executing._sort parameter to exfiltrate data from arbitrary tables:curl -X GET "https://target-openemr.com/apis/api/patient?_sort=uuid,(SELECT username FROM users WHERE id=1 LIMIT 1)--" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"patient_data, users) to extract PHI records, password hashes, and other sensitive data using blind or error-based SQL injection techniques (GitHub Advisory)./apis/api/patient with _sort parameter values containing SQL syntax (e.g., SELECT, SLEEP, --, parentheses, or subqueries); repeated API calls with varying _sort payloads from a single source IP./apis/api/patient?_sort= with encoded or plaintext SQL fragments; database slow query logs showing ORDER BY clauses containing subqueries or SQL functions (e.g., SLEEP()).ORDER BY (SELECT ...) patterns or reference tables outside normal patient data operations (GitHub Advisory).Upgrade OpenEMR to version 8.0.0 or later, which resolves the vulnerability by implementing a strict column whitelist (ALLOWED_SORT_COLUMNS) and rejecting any _sort values not on the approved list (Patch Commit). For organizations unable to patch immediately, restrict REST API access to trusted, authorized users only and implement network-level controls (e.g., firewall rules, API gateway policies) to limit exposure of the /apis/api/patient endpoint. Additionally, monitor API logs for _sort parameter values containing SQL-like syntax as a detection measure (GitHub Advisory).
The vulnerability was part of a broader batch of 38 security flaws discovered in OpenEMR, which received coverage from multiple healthcare and cybersecurity media outlets including BankInfoSecurity, HealthcareInfoSecurity, DataBreachToday, SecurityWeek, and The Hacker News (BankInfoSecurity, SecurityWeek). The discovery was attributed to security researchers at Aisle, who published a blog post highlighting the critical nature of the findings in healthcare software used by over 100,000 providers (Aisle Blog). The Hacker News also referenced the OpenEMR flaws in its weekly threat recap bulletins, indicating notable community attention to the healthcare software security implications.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."