
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32123 is an incorrect authorization vulnerability in OpenEMR, a free and open-source electronic health records (EHR) and medical practice management application. The flaw causes sensitivity access controls for group encounters (e.g., mental health/therapy sessions) to be completely unenforced, allowing low-privileged authenticated users to view restricted patient records they should be blocked from accessing. All OpenEMR versions prior to 8.0.0.1 are affected. The vulnerability was published on March 11, 2026, and fixed in version 8.0.0.1. It carries a CVSS v3.1 score of 7.7 (High) per the GitHub Security Advisory, or 6.5 (Medium) per NVD scoring (GitHub Advisory).
The root cause is an incorrect authorization flaw (CWE-863) in OpenEMR's encounter sensitivity logic, specifically in src/Services/EncounterService.php (or equivalent) within the method responsible for sensitivity lookups (e.g., getSensitivity()). The code exclusively queries the form_encounter table to determine whether an encounter is marked sensitive, but group encounters store their sensitivity designation in a separate table, form_groups_encounter. Because the sensitivity check never consults form_groups_encounter, the sensitivity flag for group encounters is effectively ignored — defaulting to non-sensitive — regardless of how the encounter was configured. An attacker with low-level authenticated network access (no special privileges beyond a standard user account) can exploit this by simply navigating to a group encounter in the patient chart, encounter list, or reports interface (GitHub Advisory).
Successful exploitation allows unauthorized staff to view sensitive Protected Health Information (PHI) contained in group encounters, including mental health, therapy, and other high-sensitivity clinical records. The confidentiality impact is high — any authenticated user with access to the group encounter interface can bypass sensitivity ACLs and read data they are explicitly prohibited from viewing. There is no integrity or availability impact, but the exposure of sensitive mental health records constitutes a serious privacy violation with potential HIPAA compliance implications for affected healthcare organizations (GitHub Advisory).
A proof-of-concept (PoC) exploit with a concrete 4-step reproduction sequence is publicly available in the GitHub Security Advisory, demonstrating how to trigger the authorization bypass on a real OpenEMR deployment. The EPSS score is approximately 0.028%, indicating low predicted exploitation probability in the near term. There is no current evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
form_groups_encounter and therefore always defaults to treating the encounter as non-sensitive (GitHub Advisory).form_groups_encounter records associated with high-sensitivity encounters originating from user sessions that lack the appropriate sensitivity ACL permissions, visible in database audit logs if enabled.The vulnerability is fixed in OpenEMR version 8.0.0.1; all users should upgrade immediately. The fix requires updating the encounter sensitivity logic to detect group encounters and derive sensitivity from form_groups_encounter (instead of, or in addition to, form_encounter), applying the same ACL checks to both encounter types. As an interim workaround prior to patching, administrators should restrict access to group encounter interfaces through role-based access configuration reviews and consider implementing database-level controls to limit exposure of sensitive encounter data (GitHub Advisory).
The vulnerability was reported by researchers pavelkohout396 (reporter) and simecek and stanislavfort (analysts) from Aisle, which published a broader blog post noting the discovery of 38 critical security vulnerabilities in healthcare software used by 100,000 providers. A Bluesky post from cyberhub.blog and coverage on infinitsec.net highlighted the ACL enforcement failure in OpenEMR's therapy group sensitivity feature. The vulnerability received attention in the security community given its direct impact on PHI and HIPAA-regulated healthcare environments (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."