
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25929 is an Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR's document controller that allows authenticated users to retrieve patient photos belonging to other patients without authorization. It affects all OpenEMR versions prior to 8.0.0 and was disclosed on February 25, 2026, with a fix released in version 8.0.0. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat).
The root cause is an Authorization Bypass Through User-Controlled Key (CWE-639) in controllers/C_Document.class.php. In the retrieve_action() method, when the $context parameter equals patient_picture (lines 631–634), the code resolves the document by calling $this->patientService->getPatientPictureDocumentId($patient_id) where $patient_id is taken directly from the HTTP request. The only access check performed is Document::can_access(), which validates only the document category ACL — it does not verify that the requesting user is authorized to access the specific patient identified by $patient_id. This means any authenticated user with document read permissions can supply an arbitrary patient ID to retrieve that patient's photo (GitHub Advisory, Patch Commit).
Successful exploitation results in unauthorized access to patient photographs, which constitute Protected Health Information (PHI) under healthcare privacy regulations such as HIPAA. Any authenticated user with document ACL permissions can enumerate and retrieve photos for any patient in the system, affecting all patient records stored in the OpenEMR instance. There is no integrity or availability impact — the vulnerability is limited to confidentiality, but the exposure of medical PHI can have significant legal, regulatory, and reputational consequences for affected healthcare organizations (GitHub Advisory).
A proof-of-concept (PoC) exploit is publicly documented in the GitHub Security Advisory, demonstrating the exact HTTP request pattern needed to exploit the vulnerability. There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.028% (0.000280), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (GitHub Advisory).
patient_picture context and the target patient's ID, for example:GET /controller.php?document&retrieve&patient_id=456&document_id=-1&as_file=false&original_file=true&disable_exit=false&show_original=true&context=patient_picture HTTP/1.1
Host: target-openemr.com
Cookie: <valid session cookie>Setting document_id=-1 forces the controller to resolve the photo by patient_id rather than a specific document ID.patient_id values to systematically harvest photos for all patients in the system (GitHub Advisory)./controller.php with parameters context=patient_picture, document_id=-1, and varying patient_id values from a single authenticated session; sequential or rapid enumeration of patient IDs in document controller requests."An attempt was made to retrieve a patient picture for an unauthorized patient" (generated by the patched version); audit log entries with event type security-access and description "Unauthorized attempt to retrieve patient picture for pid <id>" (post-patch).context=patient_picture and different patient_id values from the same session or IP address, particularly outside normal business hours.The primary remediation is to upgrade OpenEMR to version 8.0.0 or later, which adds a session-based patient authorization check in retrieve_action() that ensures non-portal users can only request photos for the currently active session patient. As a temporary workaround for organizations unable to patch immediately, restrict document ACL permissions to only essential personnel and implement enhanced monitoring of document controller access logs for anomalous patient ID patterns. The fix commit (fc4d00e) adds a 403 response and audit log entry for unauthorized access attempts (Patch Commit, GitHub Advisory).
The vulnerability was reported by security researchers simecek (reporter) and pavelkohout396 (analyst), with remediation developed by kojiromike and committed by OpenEMR maintainer bradymiller. Red Hat tracked the advisory through their security CVE database. An Aisle security blog post from May 2026 referenced this and related vulnerabilities as part of a broader disclosure of 38 security issues found in healthcare software used by 100,000 providers, highlighting systemic access control weaknesses in OpenEMR (GitHub Advisory, Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."