CVE-2026-25744: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-25744 is an authorization bypass vulnerability in OpenEMR's encounter vitals REST API that allows authenticated users to tamper with any patient's vital signs records. Affecting all versions prior to 8.0.0.2, the flaw was disclosed on March 19, 2026, and patched in version 8.0.0.2. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).

Technical details

The root cause is an Insecure Direct Object Reference (IDOR) flaw classified as CWE-639 (Authorization Bypass Through User-Controlled Key). The encounter vitals API endpoint (POST /api/encounter/{pid}/{eid}/vital) accepts an id field in the request body and interprets its presence as an UPDATE operation via EncounterService::insertVital() → VitalsService::save(). Critically, the update is keyed solely on the user-supplied id with no validation that the referenced vital record belongs to the authenticated user's authorized patient (pid) or encounter (eid). The vulnerable code path spans src/RestControllers/EncounterRestController.php, src/Services/EncounterService.php, and src/Services/VitalsService.php. The fix adds ownership verification in both the REST API's updateVital() method and the legacy vitals form save path (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated attacker to overwrite vital signs records — including blood pressure, weight, and height — for any patient in the system, regardless of whether they are authorized to access that patient's records. This constitutes medical record tampering with direct clinical consequences, as corrupted vitals (e.g., falsified blood pressure or weight) can adversely influence treatment decisions. There is no confidentiality or availability impact; the vulnerability is limited to integrity of patient health data (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, including a concrete HTTP request example and numbered reproduction steps. No in-the-wild exploitation has been observed as of the time of disclosure. The EPSS score is approximately 0.026%, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication with encounters/notes or vitals permission, limiting the attacker pool to internal or compromised accounts (GitHub Advisory).

Exploitation steps

  1. Authenticate: Log in to the target OpenEMR instance as a user with encounters/notes or vitals permission.
  2. Enumerate vital IDs: Use a legitimate API endpoint or sequential ID guessing to identify a vital record id belonging to a different patient (e.g., vital_id = 999).
  3. Craft malicious POST request: Send a POST request to an encounter the attacker is authorized to access, embedding the target vital's id in the request body:
POST /api/encounter/{pid}/{eid}/vital HTTP/1.1
Host: target-openemr.com
Authorization: Bearer <token>
Content-Type: application/json

{"id": 999, "bps": "120", "bpd": "80", "weight": "70", "height": "175"}
  1. Verify tampering: Confirm that the vital record with id=999 (belonging to another patient) has been overwritten with the attacker-supplied values by reading that patient's vitals through another endpoint or the UI (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /api/encounter/{pid}/{eid}/vital where the pid/eid in the URL path does not correspond to the patient whose vital id is referenced in the request body; repeated API calls to the vitals endpoint with varying id values in rapid succession.
  • Logs: OpenEMR API access logs showing a single authenticated user account making POST requests to vitals endpoints for multiple different patient IDs in a short timeframe; requests containing an id field in the POST body to the vitals endpoint (pre-patch behavior).
  • Application: Unexpected changes to vital signs records for patients not recently seen by the modifying user; discrepancies between vitals recorded in the UI and those stored in the database for specific records.

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0.2 or later, which adds ownership verification in EncounterService::updateVital() and the legacy vitals form save path to ensure vitals can only be updated if the record's pid and eid match the authorized patient and encounter. No configuration-based workaround is available for unpatched versions. As supplementary measures, audit vital signs records for unauthorized modifications and review API access logs for suspicious cross-patient vitals activity. Restrict the encounters/notes permission to only trusted clinical staff (GitHub Advisory, Patch Commit).

Community reactions

The vulnerability was discovered and reported by researchers simecek, stanislavfortaisle, and pavelkohout396 (associated with Aisle), who published a broader blog post noting the discovery of 38 security vulnerabilities in healthcare software used by 100,000 providers. Remediation was handled by kojiromike and reviewed by bradymiller from the OpenEMR project (GitHub Advisory, Aisle Blog).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management