CVE-2026-25929: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-25929 is an Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR's document controller that allows authenticated users to retrieve patient photos belonging to other patients without authorization. It affects all OpenEMR versions prior to 8.0.0 and was disclosed on February 25, 2026, with a fix released in version 8.0.0. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat).

Technical details

The root cause is an Authorization Bypass Through User-Controlled Key (CWE-639) in controllers/C_Document.class.php. In the retrieve_action() method, when the $context parameter equals patient_picture (lines 631–634), the code resolves the document by calling $this->patientService->getPatientPictureDocumentId($patient_id) where $patient_id is taken directly from the HTTP request. The only access check performed is Document::can_access(), which validates only the document category ACL — it does not verify that the requesting user is authorized to access the specific patient identified by $patient_id. This means any authenticated user with document read permissions can supply an arbitrary patient ID to retrieve that patient's photo (GitHub Advisory, Patch Commit).

Impact

Successful exploitation results in unauthorized access to patient photographs, which constitute Protected Health Information (PHI) under healthcare privacy regulations such as HIPAA. Any authenticated user with document ACL permissions can enumerate and retrieve photos for any patient in the system, affecting all patient records stored in the OpenEMR instance. There is no integrity or availability impact — the vulnerability is limited to confidentiality, but the exposure of medical PHI can have significant legal, regulatory, and reputational consequences for affected healthcare organizations (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) exploit is publicly documented in the GitHub Security Advisory, demonstrating the exact HTTP request pattern needed to exploit the vulnerability. There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.028% (0.000280), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (GitHub Advisory).

Exploitation steps

  1. Authentication: Log in to the target OpenEMR instance as any user account that has document or patient read ACL permissions.
  2. Patient ID Enumeration: Identify target patient IDs through legitimate access (e.g., visible in report URLs, demographics pages, or sequential enumeration of integer IDs).
  3. Craft Malicious Request: Construct an HTTP GET request targeting the document controller with the patient_picture context and the target patient's ID, for example:
    GET /controller.php?document&retrieve&patient_id=456&document_id=-1&as_file=false&original_file=true&disable_exit=false&show_original=true&context=patient_picture HTTP/1.1
    Host: target-openemr.com
    Cookie: <valid session cookie>
    Setting document_id=-1 forces the controller to resolve the photo by patient_id rather than a specific document ID.
  4. Retrieve PHI: If the server returns image bytes or redirects to the patient's photo, the IDOR is confirmed and the attacker has successfully retrieved another patient's photograph without authorization.
  5. Mass Enumeration: Repeat step 3 with incrementing patient_id values to systematically harvest photos for all patients in the system (GitHub Advisory).

Indicators of compromise

  • Network: Repeated HTTP GET requests to /controller.php with parameters context=patient_picture, document_id=-1, and varying patient_id values from a single authenticated session; sequential or rapid enumeration of patient IDs in document controller requests.
  • Logs: OpenEMR application logs showing the warning message "An attempt was made to retrieve a patient picture for an unauthorized patient" (generated by the patched version); audit log entries with event type security-access and description "Unauthorized attempt to retrieve patient picture for pid <id>" (post-patch).
  • Logs (pre-patch): Web server access logs showing high volumes of requests to the document controller endpoint with context=patient_picture and different patient_id values from the same session or IP address, particularly outside normal business hours.
  • Process/Session: A single authenticated user session accessing patient picture records for a large number of distinct patient IDs in a short time window (GitHub Advisory, Patch Commit).

Mitigation and workarounds

The primary remediation is to upgrade OpenEMR to version 8.0.0 or later, which adds a session-based patient authorization check in retrieve_action() that ensures non-portal users can only request photos for the currently active session patient. As a temporary workaround for organizations unable to patch immediately, restrict document ACL permissions to only essential personnel and implement enhanced monitoring of document controller access logs for anomalous patient ID patterns. The fix commit (fc4d00e) adds a 403 response and audit log entry for unauthorized access attempts (Patch Commit, GitHub Advisory).

Community reactions

The vulnerability was reported by security researchers simecek (reporter) and pavelkohout396 (analyst), with remediation developed by kojiromike and committed by OpenEMR maintainer bradymiller. Red Hat tracked the advisory through their security CVE database. An Aisle security blog post from May 2026 referenced this and related vulnerabilities as part of a broader disclosure of 38 security issues found in healthcare software used by 100,000 providers, highlighting systemic access control weaknesses in OpenEMR (GitHub Advisory, Red Hat).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management