CVE-2026-25928: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-25928 is a path traversal vulnerability in OpenEMR's DICOM zip/export feature that allows an authenticated attacker with DICOM upload/export permissions to write files outside the intended directory, potentially enabling remote code execution. It affects all OpenEMR versions prior to 8.0.0.2 and was disclosed on March 19, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In controllers/C_Document.class.php, the upload_action_process() function sets $study_name directly from the user-supplied $_POST['destination'] parameter, applying only whitespace normalization (preg_replace('/\s+/', '_', $study_name)) without stripping path traversal sequences such as ../. The resulting $study_name is then concatenated with $GLOBALS['temporary_files_dir'] and passed to ZipArchive::open(), allowing an attacker to escape the intended temporary directory. A secondary traversal vector existed in uploaded DICOM filenames, which were also not sanitized before being written to disk (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated attacker to write arbitrary files to any location accessible by the web server process, including the web root. If PHP or other executable files are written under the web root, this escalates to full remote code execution, enabling complete server compromise, access to sensitive patient health records (EHR data), and potential lateral movement within the healthcare network. Confidentiality impact is rated None in the base CVSS score, but RCE via a written web shell would effectively expose all data on the system (GitHub Advisory).

Exploitability

A proof-of-concept exploit with step-by-step attack instructions and a concrete HTTP request example is publicly available in the GitHub Security Advisory (GitHub Advisory). Exploitation requires low privileges (a valid account with DICOM upload/export permission) and no user interaction. The EPSS score is approximately 0.082%, and there is no confirmed evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Feedly).

Exploitation steps

  1. Reconnaissance: Identify an internet-facing OpenEMR instance running a version prior to 8.0.0.2. Confirm the DICOM upload/export feature is enabled.
  2. Obtain credentials: Log in with a user account that has document upload permission and access to a patient context (e.g., a low-privileged clinical user).
  3. Craft malicious request: Prepare a multipart HTTP POST request to /controller.php?document&patient_id=<id> with the destination parameter set to a path traversal sequence such as ../../public/evil, and include one or more DICOM files in the dicom_folder[] field.
  4. Trigger file write: Submit the request. The server concatenates the unsanitized destination value with temporary_files_dir, causing the zip file to be created outside the intended directory (e.g., under the web root at public/evil.zip).
  5. Escalate to RCE: If the target path is web-accessible and PHP execution is permitted, upload a DICOM file named ../../../var/www/html/shell.php (exploiting the secondary filename traversal) or craft the zip to contain a PHP web shell, then access it via the browser to achieve remote code execution (GitHub Advisory).

Indicators of compromise

  • Network: Unusual multipart POST requests to /controller.php with document action containing destination parameters including ../ sequences; outbound connections from the web server to unknown external IPs following a DICOM upload.
  • File System: Unexpected .zip, .php, or other files appearing outside the configured temporary_files_dir, particularly under the web root (e.g., public/, www/, html/); presence of web shell files (e.g., shell.php, cmd.php) in web-accessible directories.
  • Logs: Web server access logs showing POST requests to /controller.php?document with encoded ../ sequences in the body; PHP error logs referencing ZipArchive::open() calls with paths outside the temp directory.
  • Process: Unexpected child processes spawned by the PHP/Apache process (e.g., bash, curl, wget, python) following a DICOM upload event (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0.2 or later, which resolves the issue by applying basename() to uploaded DICOM filenames and canonicalizing the zip destination path to restrict it to the whitelisted base directory (Patch Commit). As interim mitigations, restrict DICOM upload/export permissions to only trusted users, configure the web server to prevent execution of files in upload/temp directories, and consider disabling the DICOM export feature entirely if not actively used. Implementing a web application firewall rule to block ../ sequences in multipart form data can also reduce exposure (GitHub Advisory).

Community reactions

The vulnerability was reported by researchers simecek, pavelkohout396, and stanislavfortaisle, with remediation developed by kojiromike (GitHub Advisory). Security firm Aisle published a blog post highlighting this and 37 other critical vulnerabilities discovered in healthcare software used by 100,000+ providers, drawing broader attention to OpenEMR's security posture (Aisle Blog). Red Hat also tracked the CVE in their security advisory database (Red Hat).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management