CVE-2026-25220: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-25220 is an authorization bypass vulnerability in OpenEMR's Message Center that allows any authenticated user to view all internal messages regardless of their privilege level. Affecting all OpenEMR versions prior to 8.0.0, the flaw was disclosed on February 25, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 5.7 (Medium) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is an authorization bypass through a user-controlled key (CWE-639) in interface/main/messages/messages.php. The application reads the show_all parameter directly from $_GET['show_all'] for all users (lines 205–206) and passes it to getPnotesByUser() without verifying that the requesting user holds administrator privileges. In library/pnotes.inc.php (lines 104–110), when $show_all == 'yes', the SQL query uses LIKE '_%' for the assigned_to field, effectively returning all messages from all users. The admin check in the code only gates the UI label and link text — it never forces $show_all to 'no' for non-admin users before the database call is made. Additionally, the "Show All" link is rendered in the UI for all authenticated users, making the attack trivially discoverable (GitHub Advisory, Patch Commit).

Impact

Successful exploitation exposes the entire internal message list to any authenticated user, including patient-related notes, staff communications, and other Protected Health Information (PHI) that should be restricted to administrators. This constitutes a significant confidentiality breach with direct HIPAA compliance implications, as unauthorized staff (e.g., nurses, billing clerks, front desk personnel) can read messages assigned to other users and patients. There is no impact on integrity or availability, but the exposure of PHI across all users in a healthcare environment represents a serious regulatory and reputational risk (GitHub Advisory).

Exploitability

A proof-of-concept is publicly documented in the GitHub Security Advisory, demonstrating that exploitation requires only a valid authenticated session and a single crafted URL request. There is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.038% (0.000380), indicating low predicted exploitation probability in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Authenticate: Log in to the target OpenEMR instance as any valid user — no administrator or special ACL privileges are required (e.g., a nurse, billing, or front desk account).
  2. Navigate to Message Center: Access the Message Center at https://target-openemr.com/interface/main/messages/messages.php.
  3. Inject the parameter: Append ?show_all=yes to the URL, resulting in: https://target-openemr.com/interface/main/messages/messages.php?show_all=yes. Alternatively, click the "Show All" link if visible in the UI (it is rendered for all users in vulnerable versions).
  4. Observe unauthorized data: The page renders the full internal message list for all users — including patient notes, staff communications, assignee names, and patient references — without any access denied response.
  5. Exfiltrate PHI: Browse or scrape the paginated message list to collect sensitive internal communications and patient-related notes from all staff accounts (GitHub Advisory).

Indicators of compromise

  • Network: HTTP GET requests to /interface/main/messages/messages.php?show_all=yes originating from non-administrator user sessions.
  • Logs: Web server access logs showing repeated or automated requests to messages.php with the show_all=yes query parameter from accounts that are not in the admin/super ACL group; unusually high volume of requests to this endpoint from a single low-privilege account.
  • Application Logs: OpenEMR audit logs (if enabled) recording access to the full message list by non-admin users, particularly outside of normal business hours.

Mitigation and workarounds

Upgrade all OpenEMR installations to version 8.0.0 or later, which resolves the issue by forcing $show_all to "no" for non-admin users before the database query is executed (a one-line fix in messages.php). No configuration-based workaround is available for unpatched versions. Organizations should also audit web server access logs for historical requests to messages.php?show_all=yes from non-administrator accounts to assess potential prior exposure (GitHub Advisory, Patch Commit).

Community reactions

The vulnerability was reported by security researchers simecek (reporter) and pavelkohout396 (analyst), with remediation developed by kojiromike and committed by OpenEMR maintainer bradymiller. Aisle published a blog post highlighting this and other vulnerabilities as part of a broader disclosure of 38 security issues found in healthcare software used by 100,000+ providers (Aisle Blog). No significant broader media coverage or social media discussion has been identified beyond the GitHub advisory and vulnerability database entries.

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management