
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25744 is an authorization bypass vulnerability in OpenEMR's encounter vitals REST API that allows authenticated users to tamper with any patient's vital signs records. Affecting all versions prior to 8.0.0.2, the flaw was disclosed on March 19, 2026, and patched in version 8.0.0.2. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The root cause is an Insecure Direct Object Reference (IDOR) flaw classified as CWE-639 (Authorization Bypass Through User-Controlled Key). The encounter vitals API endpoint (POST /api/encounter/{pid}/{eid}/vital) accepts an id field in the request body and interprets its presence as an UPDATE operation via EncounterService::insertVital() → VitalsService::save(). Critically, the update is keyed solely on the user-supplied id with no validation that the referenced vital record belongs to the authenticated user's authorized patient (pid) or encounter (eid). The vulnerable code path spans src/RestControllers/EncounterRestController.php, src/Services/EncounterService.php, and src/Services/VitalsService.php. The fix adds ownership verification in both the REST API's updateVital() method and the legacy vitals form save path (GitHub Advisory, Patch Commit).
Successful exploitation allows an authenticated attacker to overwrite vital signs records — including blood pressure, weight, and height — for any patient in the system, regardless of whether they are authorized to access that patient's records. This constitutes medical record tampering with direct clinical consequences, as corrupted vitals (e.g., falsified blood pressure or weight) can adversely influence treatment decisions. There is no confidentiality or availability impact; the vulnerability is limited to integrity of patient health data (GitHub Advisory).
A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, including a concrete HTTP request example and numbered reproduction steps. No in-the-wild exploitation has been observed as of the time of disclosure. The EPSS score is approximately 0.026%, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication with encounters/notes or vitals permission, limiting the attacker pool to internal or compromised accounts (GitHub Advisory).
encounters/notes or vitals permission.id belonging to a different patient (e.g., vital_id = 999).id in the request body:POST /api/encounter/{pid}/{eid}/vital HTTP/1.1
Host: target-openemr.com
Authorization: Bearer <token>
Content-Type: application/json
{"id": 999, "bps": "120", "bpd": "80", "weight": "70", "height": "175"}id=999 (belonging to another patient) has been overwritten with the attacker-supplied values by reading that patient's vitals through another endpoint or the UI (GitHub Advisory)./api/encounter/{pid}/{eid}/vital where the pid/eid in the URL path does not correspond to the patient whose vital id is referenced in the request body; repeated API calls to the vitals endpoint with varying id values in rapid succession.id field in the POST body to the vitals endpoint (pre-patch behavior).Upgrade OpenEMR to version 8.0.0.2 or later, which adds ownership verification in EncounterService::updateVital() and the legacy vitals form save path to ensure vitals can only be updated if the record's pid and eid match the authorized patient and encounter. No configuration-based workaround is available for unpatched versions. As supplementary measures, audit vital signs records for unauthorized modifications and review API access logs for suspicious cross-patient vitals activity. Restrict the encounters/notes permission to only trusted clinical staff (GitHub Advisory, Patch Commit).
The vulnerability was discovered and reported by researchers simecek, stanislavfortaisle, and pavelkohout396 (associated with Aisle), who published a broader blog post noting the discovery of 38 security vulnerabilities in healthcare software used by 100,000 providers. Remediation was handled by kojiromike and reviewed by bradymiller from the OpenEMR project (GitHub Advisory, Aisle Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."