
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25220 is an authorization bypass vulnerability in OpenEMR's Message Center that allows any authenticated user to view all internal messages regardless of their privilege level. Affecting all OpenEMR versions prior to 8.0.0, the flaw was disclosed on February 25, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 5.7 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is an authorization bypass through a user-controlled key (CWE-639) in interface/main/messages/messages.php. The application reads the show_all parameter directly from $_GET['show_all'] for all users (lines 205–206) and passes it to getPnotesByUser() without verifying that the requesting user holds administrator privileges. In library/pnotes.inc.php (lines 104–110), when $show_all == 'yes', the SQL query uses LIKE '_%' for the assigned_to field, effectively returning all messages from all users. The admin check in the code only gates the UI label and link text — it never forces $show_all to 'no' for non-admin users before the database call is made. Additionally, the "Show All" link is rendered in the UI for all authenticated users, making the attack trivially discoverable (GitHub Advisory, Patch Commit).
Successful exploitation exposes the entire internal message list to any authenticated user, including patient-related notes, staff communications, and other Protected Health Information (PHI) that should be restricted to administrators. This constitutes a significant confidentiality breach with direct HIPAA compliance implications, as unauthorized staff (e.g., nurses, billing clerks, front desk personnel) can read messages assigned to other users and patients. There is no impact on integrity or availability, but the exposure of PHI across all users in a healthcare environment represents a serious regulatory and reputational risk (GitHub Advisory).
A proof-of-concept is publicly documented in the GitHub Security Advisory, demonstrating that exploitation requires only a valid authenticated session and a single crafted URL request. There is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.038% (0.000380), indicating low predicted exploitation probability in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Red Hat CVE).
https://target-openemr.com/interface/main/messages/messages.php.?show_all=yes to the URL, resulting in: https://target-openemr.com/interface/main/messages/messages.php?show_all=yes. Alternatively, click the "Show All" link if visible in the UI (it is rendered for all users in vulnerable versions)./interface/main/messages/messages.php?show_all=yes originating from non-administrator user sessions.messages.php with the show_all=yes query parameter from accounts that are not in the admin/super ACL group; unusually high volume of requests to this endpoint from a single low-privilege account.Upgrade all OpenEMR installations to version 8.0.0 or later, which resolves the issue by forcing $show_all to "no" for non-admin users before the database query is executed (a one-line fix in messages.php). No configuration-based workaround is available for unpatched versions. Organizations should also audit web server access logs for historical requests to messages.php?show_all=yes from non-administrator accounts to assess potential prior exposure (GitHub Advisory, Patch Commit).
The vulnerability was reported by security researchers simecek (reporter) and pavelkohout396 (analyst), with remediation developed by kojiromike and committed by OpenEMR maintainer bradymiller. Aisle published a blog post highlighting this and other vulnerabilities as part of a broader disclosure of 38 security issues found in healthcare software used by 100,000+ providers (Aisle Blog). No significant broader media coverage or social media discussion has been identified beyond the GitHub advisory and vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."