CVE-2026-32122: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-32122 is a Missing Authorization vulnerability in OpenEMR's Claim File Tracker AJAX endpoint that allows authenticated users without billing permissions to access sensitive billing claim metadata. It affects all OpenEMR versions prior to 8.0.0.1 and was disclosed on March 11, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): the AJAX endpoint at library/ajax/billing_tracker_ajax.php only validates the CSRF token but does not perform the same ACL check (AclMain::aclCheckCore('acct', 'eob', '', 'write') or aclCheckCore('acct', 'bill', '', 'write')) that the corresponding UI at interface/billing/billing_tracker.php enforces. As a result, any authenticated user — regardless of their role — can send a crafted HTTP GET request to the endpoint and receive billing claim metadata including claim IDs, payer information (x12_partner_id, x12_filename), transmission status, and logs. The attack requires only a valid session cookie and a CSRF token, both obtainable by any logged-in user (GitHub Advisory).

Impact

Successful exploitation results in unauthorized disclosure of sensitive billing and claims data — including claim IDs, payer names, transmission state, and associated messages — to any authenticated user regardless of their assigned role (e.g., front desk staff or nurses). There is no integrity or availability impact; the vulnerability is limited to confidentiality. Exposed billing metadata could facilitate social engineering attacks or further abuse of patient and payer information in healthcare environments (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) reproduction guide is publicly available in the GitHub Security Advisory, detailing the exact HTTP request needed to trigger the vulnerability. The EPSS score is approximately 0.021%, indicating low predicted exploitation probability at this time. There is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Obtain credentials: Log in to the target OpenEMR instance as any authenticated user without billing/claims permissions (e.g., a front desk or nursing account).
  2. Retrieve CSRF token: Open browser developer tools (Network tab) and navigate to any OpenEMR page to capture a valid csrf_token_form value from existing requests or page source.
  3. Craft the request: Send a direct HTTP GET request to the vulnerable AJAX endpoint:
GET /library/ajax/billing_tracker_ajax.php?csrf_token_form=<token> HTTP/1.1
Host: target-openemr.com
Cookie: <session_cookie>
X-Requested-With: XMLHttpRequest
  1. Verify exploitation: If the endpoint returns claim tracking data (claim IDs, payer names, status, transmission info) rather than a 403 Forbidden response, the instance is vulnerable and billing metadata has been successfully extracted (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP GET requests to /library/ajax/billing_tracker_ajax.php originating from user accounts not associated with billing roles; requests with X-Requested-With: XMLHttpRequest header from unusual source IPs or user agents.
  • Logs: OpenEMR access logs showing repeated or anomalous calls to billing_tracker_ajax.php by low-privilege user accounts (e.g., front desk, nursing roles); successful 200 responses to this endpoint from non-billing users.
  • Application: Audit trail entries showing billing claim data access by users whose role does not include acct/eob or acct/bill permissions.

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0.1 or later, which adds a server-side ACL check (AclMain::aclCheckCore('acct', 'bill') or equivalent) at the start of the Claim File Tracker AJAX handler and returns HTTP 403 for unauthorized users. As a temporary workaround if immediate patching is not possible, implement network-level access controls (e.g., firewall rules or web server configuration) to restrict direct access to library/ajax/billing_tracker_ajax.php to only authorized IP ranges or roles. Additionally, review audit logs for unauthorized access to billing claim data prior to patching (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher pavelkohout396 and analyzed by simecek and stanislavfortaisle from Aisle, which published a broader blog post noting the discovery of 38 security vulnerabilities in OpenEMR affecting over 100,000 healthcare providers. No significant broader media coverage or social media discussion has been identified beyond the GitHub advisory and security aggregator listings (GitHub Advisory, Aisle Blog).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management