CVE-2026-25127: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-25127 is a Broken Access Control (Incorrect Authorization) vulnerability in OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. Prior to version 8.0.0, the server fails to properly validate user permissions, allowing authenticated low-privileged users to access data restricted to higher-privileged roles. The vulnerability was disclosed on February 25, 2026, and affects all OpenEMR versions before 8.0.0. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-863 (Incorrect Authorization): the message_list.php report endpoint and the Care Coordination module's encounter manager endpoint (/interface/modules/zend_modules/public/encountermanager) lacked Access Control List (ACL) enforcement checks. Any authenticated user could substitute their session cookie in requests intended for higher-privileged roles and successfully retrieve restricted data. The fix adds an AclMain::aclCheckCore('patients', 'med') check to message_list.php, rendering an unauthorized page for users without the required ACL permissions (GitHub Commit, GitHub Advisory).

Impact

Successful exploitation allows a low-privileged authenticated user (e.g., an Accounting role user) to access sensitive data belonging to higher-privileged users or restricted modules, including patient messages, protected health information (PHI), and Care Coordination records. The vulnerability has no impact on data integrity or system availability, but poses a significant confidentiality risk. In healthcare environments, unauthorized access to PHI may constitute a HIPAA violation and expose organizations to regulatory penalties and reputational harm (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid low-privileged account on the target OpenEMR instance, limiting the attack surface to authenticated users (GitHub Advisory, Feedly).

Exploitation steps

  1. Obtain a low-privileged account: Log in to the target OpenEMR instance using any valid account (e.g., an Accounting role user such as accountant) that does not have access to the Care Coordination module or message list report.
  2. Capture a privileged request: Using a proxy tool (e.g., Burp Suite), observe or obtain an HTTP request made by an Administrator account to a restricted endpoint such as https://<target>/openemr/interface/modules/zend_modules/public/encountermanager or https://<target>/openemr/interface/reports/message_list.php.
  3. Substitute session cookie: Replace the Administrator's session cookie in the captured request with the low-privileged user's session cookie (e.g., KbJquQEOD4mH0fwRHKY13rFhsRjbEvqVqezbx2mMbVbzdnPd).
  4. Send the modified request: Forward the modified request to the server. Due to the missing ACL check, the server processes the request and returns restricted Care Coordination or patient message data.
  5. Exfiltrate data: Review or export the returned data, which may include patient PHI, encounter records, or message lists in CSV format (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: HTTP GET/POST requests to /openemr/interface/modules/zend_modules/public/encountermanager or /openemr/interface/reports/message_list.php from session cookies associated with low-privileged accounts (e.g., Accounting role).
  • Logs: OpenEMR access logs showing requests to restricted module endpoints from user accounts not assigned the Administrator or appropriate ACL role; repeated access to message_list.php from non-clinical accounts.
  • Application Behavior: Successful HTTP 200 responses to Care Coordination or message list endpoints for accounts that should receive an unauthorized/403 response; CSV exports of patient message data initiated by non-clinical user accounts.

Mitigation and workarounds

Upgrade all OpenEMR installations to version 8.0.0 or later, which adds proper ACL enforcement to the affected endpoints (GitHub Advisory, GitHub Commit). Until patching is possible, implement network segmentation to restrict access to OpenEMR instances to authorized personnel only, and review user account roles to enforce the principle of least privilege. Enable and monitor access logs for suspicious requests to restricted module endpoints from low-privileged accounts.

Community reactions

The vulnerability was reported by security researcher(s) credited as "Knock-pt" and was published via GitHub's security advisory program by OpenEMR maintainer bradymiller on February 25, 2026 (GitHub Advisory). Red Hat tracked the advisory for awareness (Red Hat CVE). No significant broader media coverage or notable social media discussion has been identified.

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management