
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25127 is a Broken Access Control (Incorrect Authorization) vulnerability in OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. Prior to version 8.0.0, the server fails to properly validate user permissions, allowing authenticated low-privileged users to access data restricted to higher-privileged roles. The vulnerability was disclosed on February 25, 2026, and affects all OpenEMR versions before 8.0.0. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, Feedly).
The root cause is CWE-863 (Incorrect Authorization): the message_list.php report endpoint and the Care Coordination module's encounter manager endpoint (/interface/modules/zend_modules/public/encountermanager) lacked Access Control List (ACL) enforcement checks. Any authenticated user could substitute their session cookie in requests intended for higher-privileged roles and successfully retrieve restricted data. The fix adds an AclMain::aclCheckCore('patients', 'med') check to message_list.php, rendering an unauthorized page for users without the required ACL permissions (GitHub Commit, GitHub Advisory).
Successful exploitation allows a low-privileged authenticated user (e.g., an Accounting role user) to access sensitive data belonging to higher-privileged users or restricted modules, including patient messages, protected health information (PHI), and Care Coordination records. The vulnerability has no impact on data integrity or system availability, but poses a significant confidentiality risk. In healthcare environments, unauthorized access to PHI may constitute a HIPAA violation and expose organizations to regulatory penalties and reputational harm (GitHub Advisory, Feedly).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid low-privileged account on the target OpenEMR instance, limiting the attack surface to authenticated users (GitHub Advisory, Feedly).
accountant) that does not have access to the Care Coordination module or message list report.https://<target>/openemr/interface/modules/zend_modules/public/encountermanager or https://<target>/openemr/interface/reports/message_list.php.KbJquQEOD4mH0fwRHKY13rFhsRjbEvqVqezbx2mMbVbzdnPd)./openemr/interface/modules/zend_modules/public/encountermanager or /openemr/interface/reports/message_list.php from session cookies associated with low-privileged accounts (e.g., Accounting role).message_list.php from non-clinical accounts.Upgrade all OpenEMR installations to version 8.0.0 or later, which adds proper ACL enforcement to the affected endpoints (GitHub Advisory, GitHub Commit). Until patching is possible, implement network segmentation to restrict access to OpenEMR instances to authorized personnel only, and review user account roles to enforce the principle of least privilege. Enable and monitor access logs for suspicious requests to restricted module endpoints from low-privileged accounts.
The vulnerability was reported by security researcher(s) credited as "Knock-pt" and was published via GitHub's security advisory program by OpenEMR maintainer bradymiller on February 25, 2026 (GitHub Advisory). Red Hat tracked the advisory for awareness (Red Hat CVE). No significant broader media coverage or notable social media discussion has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."