CVE-2026-32123: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-32123 is an incorrect authorization vulnerability in OpenEMR, a free and open-source electronic health records (EHR) and medical practice management application. The flaw causes sensitivity access controls for group encounters (e.g., mental health/therapy sessions) to be completely unenforced, allowing low-privileged authenticated users to view restricted patient records they should be blocked from accessing. All OpenEMR versions prior to 8.0.0.1 are affected. The vulnerability was published on March 11, 2026, and fixed in version 8.0.0.1. It carries a CVSS v3.1 score of 7.7 (High) per the GitHub Security Advisory, or 6.5 (Medium) per NVD scoring (GitHub Advisory).

Technical details

The root cause is an incorrect authorization flaw (CWE-863) in OpenEMR's encounter sensitivity logic, specifically in src/Services/EncounterService.php (or equivalent) within the method responsible for sensitivity lookups (e.g., getSensitivity()). The code exclusively queries the form_encounter table to determine whether an encounter is marked sensitive, but group encounters store their sensitivity designation in a separate table, form_groups_encounter. Because the sensitivity check never consults form_groups_encounter, the sensitivity flag for group encounters is effectively ignored — defaulting to non-sensitive — regardless of how the encounter was configured. An attacker with low-level authenticated network access (no special privileges beyond a standard user account) can exploit this by simply navigating to a group encounter in the patient chart, encounter list, or reports interface (GitHub Advisory).

Impact

Successful exploitation allows unauthorized staff to view sensitive Protected Health Information (PHI) contained in group encounters, including mental health, therapy, and other high-sensitivity clinical records. The confidentiality impact is high — any authenticated user with access to the group encounter interface can bypass sensitivity ACLs and read data they are explicitly prohibited from viewing. There is no integrity or availability impact, but the exposure of sensitive mental health records constitutes a serious privacy violation with potential HIPAA compliance implications for affected healthcare organizations (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) exploit with a concrete 4-step reproduction sequence is publicly available in the GitHub Security Advisory, demonstrating how to trigger the authorization bypass on a real OpenEMR deployment. The EPSS score is approximately 0.028%, indicating low predicted exploitation probability in the near term. There is no current evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify an OpenEMR instance running a version prior to 8.0.0.1. Confirm that the instance uses group encounters (e.g., group therapy sessions) with sensitivity flags configured.
  2. Authentication: Log in to the OpenEMR application using a low-privileged user account that has access to group encounters but does not hold permission to view high-sensitivity (e.g., mental health) encounter data.
  3. Navigate to group encounters: Access the group encounter list, patient chart, or reports interface within OpenEMR that displays group encounter records.
  4. Open a sensitive group encounter: Select and open a group encounter that has been configured with a restricted sensitivity level (e.g., mental health/high sensitivity).
  5. Observe unauthorized access: The encounter and all associated clinical data are displayed in full, without any access denial or data redaction, because the sensitivity check never queries form_groups_encounter and therefore always defaults to treating the encounter as non-sensitive (GitHub Advisory).

Indicators of compromise

  • Logs: OpenEMR application logs showing low-privileged user accounts repeatedly accessing group encounter records, particularly those flagged with high-sensitivity designations; access patterns inconsistent with a user's normal role or patient assignment.
  • Application Behavior: Absence of access-denied events or sensitivity restriction errors in audit logs when low-privileged users access group encounters that should be restricted.
  • Database: Queries to form_groups_encounter records associated with high-sensitivity encounters originating from user sessions that lack the appropriate sensitivity ACL permissions, visible in database audit logs if enabled.

Mitigation and workarounds

The vulnerability is fixed in OpenEMR version 8.0.0.1; all users should upgrade immediately. The fix requires updating the encounter sensitivity logic to detect group encounters and derive sensitivity from form_groups_encounter (instead of, or in addition to, form_encounter), applying the same ACL checks to both encounter types. As an interim workaround prior to patching, administrators should restrict access to group encounter interfaces through role-based access configuration reviews and consider implementing database-level controls to limit exposure of sensitive encounter data (GitHub Advisory).

Community reactions

The vulnerability was reported by researchers pavelkohout396 (reporter) and simecek and stanislavfort (analysts) from Aisle, which published a broader blog post noting the discovery of 38 critical security vulnerabilities in healthcare software used by 100,000 providers. A Bluesky post from cyberhub.blog and coverage on infinitsec.net highlighted the ACL enforcement failure in OpenEMR's therapy group sensitivity feature. The vulnerability received attention in the security community given its direct impact on PHI and HIPAA-regulated healthcare environments (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management