
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25928 is a path traversal vulnerability in OpenEMR's DICOM zip/export feature that allows an authenticated attacker with DICOM upload/export permissions to write files outside the intended directory, potentially enabling remote code execution. It affects all OpenEMR versions prior to 8.0.0.2 and was disclosed on March 19, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In controllers/C_Document.class.php, the upload_action_process() function sets $study_name directly from the user-supplied $_POST['destination'] parameter, applying only whitespace normalization (preg_replace('/\s+/', '_', $study_name)) without stripping path traversal sequences such as ../. The resulting $study_name is then concatenated with $GLOBALS['temporary_files_dir'] and passed to ZipArchive::open(), allowing an attacker to escape the intended temporary directory. A secondary traversal vector existed in uploaded DICOM filenames, which were also not sanitized before being written to disk (GitHub Advisory, Patch Commit).
Successful exploitation allows an authenticated attacker to write arbitrary files to any location accessible by the web server process, including the web root. If PHP or other executable files are written under the web root, this escalates to full remote code execution, enabling complete server compromise, access to sensitive patient health records (EHR data), and potential lateral movement within the healthcare network. Confidentiality impact is rated None in the base CVSS score, but RCE via a written web shell would effectively expose all data on the system (GitHub Advisory).
A proof-of-concept exploit with step-by-step attack instructions and a concrete HTTP request example is publicly available in the GitHub Security Advisory (GitHub Advisory). Exploitation requires low privileges (a valid account with DICOM upload/export permission) and no user interaction. The EPSS score is approximately 0.082%, and there is no confirmed evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Feedly).
/controller.php?document&patient_id=<id> with the destination parameter set to a path traversal sequence such as ../../public/evil, and include one or more DICOM files in the dicom_folder[] field.destination value with temporary_files_dir, causing the zip file to be created outside the intended directory (e.g., under the web root at public/evil.zip).../../../var/www/html/shell.php (exploiting the secondary filename traversal) or craft the zip to contain a PHP web shell, then access it via the browser to achieve remote code execution (GitHub Advisory)./controller.php with document action containing destination parameters including ../ sequences; outbound connections from the web server to unknown external IPs following a DICOM upload..zip, .php, or other files appearing outside the configured temporary_files_dir, particularly under the web root (e.g., public/, www/, html/); presence of web shell files (e.g., shell.php, cmd.php) in web-accessible directories./controller.php?document with encoded ../ sequences in the body; PHP error logs referencing ZipArchive::open() calls with paths outside the temp directory.bash, curl, wget, python) following a DICOM upload event (GitHub Advisory).Upgrade OpenEMR to version 8.0.0.2 or later, which resolves the issue by applying basename() to uploaded DICOM filenames and canonicalizing the zip destination path to restrict it to the whitelisted base directory (Patch Commit). As interim mitigations, restrict DICOM upload/export permissions to only trusted users, configure the web server to prevent execution of files in upload/temp directories, and consider disabling the DICOM export feature entirely if not actively used. Implementing a web application firewall rule to block ../ sequences in multipart form data can also reduce exposure (GitHub Advisory).
The vulnerability was reported by researchers simecek, pavelkohout396, and stanislavfortaisle, with remediation developed by kojiromike (GitHub Advisory). Security firm Aisle published a blog post highlighting this and 37 other critical vulnerabilities discovered in healthcare software used by 100,000+ providers, drawing broader attention to OpenEMR's security posture (Aisle Blog). Red Hat also tracked the CVE in their security advisory database (Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."