
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32122 is a Missing Authorization vulnerability in OpenEMR's Claim File Tracker AJAX endpoint that allows authenticated users without billing permissions to access sensitive billing claim metadata. It affects all OpenEMR versions prior to 8.0.0.1 and was disclosed on March 11, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).
The root cause is CWE-862 (Missing Authorization): the AJAX endpoint at library/ajax/billing_tracker_ajax.php only validates the CSRF token but does not perform the same ACL check (AclMain::aclCheckCore('acct', 'eob', '', 'write') or aclCheckCore('acct', 'bill', '', 'write')) that the corresponding UI at interface/billing/billing_tracker.php enforces. As a result, any authenticated user — regardless of their role — can send a crafted HTTP GET request to the endpoint and receive billing claim metadata including claim IDs, payer information (x12_partner_id, x12_filename), transmission status, and logs. The attack requires only a valid session cookie and a CSRF token, both obtainable by any logged-in user (GitHub Advisory).
Successful exploitation results in unauthorized disclosure of sensitive billing and claims data — including claim IDs, payer names, transmission state, and associated messages — to any authenticated user regardless of their assigned role (e.g., front desk staff or nurses). There is no integrity or availability impact; the vulnerability is limited to confidentiality. Exposed billing metadata could facilitate social engineering attacks or further abuse of patient and payer information in healthcare environments (GitHub Advisory).
A proof-of-concept (PoC) reproduction guide is publicly available in the GitHub Security Advisory, detailing the exact HTTP request needed to trigger the vulnerability. The EPSS score is approximately 0.021%, indicating low predicted exploitation probability at this time. There is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
csrf_token_form value from existing requests or page source.GET /library/ajax/billing_tracker_ajax.php?csrf_token_form=<token> HTTP/1.1
Host: target-openemr.com
Cookie: <session_cookie>
X-Requested-With: XMLHttpRequest/library/ajax/billing_tracker_ajax.php originating from user accounts not associated with billing roles; requests with X-Requested-With: XMLHttpRequest header from unusual source IPs or user agents.billing_tracker_ajax.php by low-privilege user accounts (e.g., front desk, nursing roles); successful 200 responses to this endpoint from non-billing users.acct/eob or acct/bill permissions.Upgrade OpenEMR to version 8.0.0.1 or later, which adds a server-side ACL check (AclMain::aclCheckCore('acct', 'bill') or equivalent) at the start of the Claim File Tracker AJAX handler and returns HTTP 403 for unauthorized users. As a temporary workaround if immediate patching is not possible, implement network-level access controls (e.g., firewall rules or web server configuration) to restrict direct access to library/ajax/billing_tracker_ajax.php to only authorized IP ranges or roles. Additionally, review audit logs for unauthorized access to billing claim data prior to patching (GitHub Advisory).
The vulnerability was reported by researcher pavelkohout396 and analyzed by simecek and stanislavfortaisle from Aisle, which published a broader blog post noting the discovery of 38 security vulnerabilities in OpenEMR affecting over 100,000 healthcare providers. No significant broader media coverage or social media discussion has been identified beyond the GitHub advisory and security aggregator listings (GitHub Advisory, Aisle Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."