
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32126 is an authorization bypass vulnerability in OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. An inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be applied only to controllers that already self-enforce authorization (review, log), while leaving six other CDR controllers (alerts, ajax, edit, add, detail, browse) accessible to any authenticated user. All versions prior to 8.0.0.1 are affected; the vulnerability was introduced in commit cd290ffd68 (October 2024) and disclosed on March 11, 2026. It carries a CVSS v3.1 base score of 8.1 (High) per NVD, or 7.1 (High) per the GitHub advisory (GitHub Advisory).
The root cause is a logic inversion bug (CWE-862: Missing Authorization) in src/ClinicalDecisionRules/Interface/ControllerRouter.php. The shouldSkipAdminAcl() method returns true for the review and log controllers (which self-protect), but the route() method uses this return value directly in the condition if ($this->shouldSkipAdminAcl($controller) && !AclMain::aclCheckCore('admin', 'super')) — meaning the ACL gate fires only when shouldSkipAdminAcl is true (i.e., for already-protected controllers), and short-circuits to no check for all other controllers. An attacker needs only a valid authenticated session (any role) and can exploit the vulnerability over the network with no user interaction by sending crafted HTTP requests directly to /interface/super/rules/index.php. The advisory includes concrete PoC steps with specific HTTP requests and curl commands (GitHub Advisory).
Any authenticated OpenEMR user — regardless of role — can perform administrator-only operations on the Clinical Decision Rules (CDR) subsystem. The most critical impact is the ability to silently suppress clinical decision support alerts system-wide (e.g., drug interaction warnings, preventive care reminders), which carries direct patient safety implications. Additionally, attackers can delete or modify clinical plans and edit rule configurations, degrading CDS workflows for an entire medical practice. There is no confidentiality impact, but integrity and availability of clinical decision support data are severely affected (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub security advisory, including step-by-step HTTP requests and curl commands demonstrating the authorization bypass on a real OpenEMR instance (GitHub Advisory). As of the time of reporting, there is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.036%, reflecting low but non-zero exploitation probability. Exploitation requires only a valid authenticated session, making it accessible to any low-privileged user with an account on the system.
/interface/super/rules/ is hidden from non-admin users in the UI, but direct URL access is not blocked.alerts!submitactmgr action with parameters to disable alert flags for a target clinical rule:POST /interface/super/rules/index.php?action=alerts!submitactmgr
Content-Type: application/x-www-form-urlencoded
id[0]=rule_dm_a1c_cqm&active[0]=off&passive[0]=off&reminder[0]=off&access_control[0]=The server responds with a 302 redirect, indicating success.ajax!deletePlan action using a valid session cookie:curl -b "OpenEMR=<session_cookie>" \
"https://<target>/interface/super/rules/index.php?action=ajax!deletePlan&plan_id=<plan_id>"The targeted plan is deleted from clinical_plans, list_options, and clinical_plans_rules tables./interface/super/rules/index.php originating from non-administrative user sessions; requests with parameters such as action=alerts!submitactmgr, action=ajax!deletePlan, action=ajax!togglePlanStatus, or action=ajax!commitChanges./interface/super/rules/index.php with write-action parameters; 302 redirect responses to CDR management endpoints from low-privileged accounts.active_alert_flag, passive_alert_flag, patient_reminder_flag, or access_control columns in the clinical_rules table (especially where pid = 0, indicating system-wide changes); missing or modified records in clinical_plans, list_options, or clinical_plans_rules tables without corresponding admin activity (GitHub Advisory).Upgrade OpenEMR to version 8.0.0.1 or later, which contains the fix for the inverted boolean condition in ControllerRouter::route(). No configuration-based workaround is available, as the flaw is in application logic. As an interim measure, administrators should restrict network access to the /interface/super/rules/ path to admin-only IP ranges or require additional authentication at the web server level. After patching, review access logs and audit the clinical_rules, clinical_plans, and related tables for unauthorized modifications made by non-administrative users prior to the upgrade (GitHub Advisory).
The vulnerability was reported by researcher pavelkohout396 and analyzed by simecek, with the advisory published by kojiromike on the OpenEMR GitHub repository. Security blog Infinitsec.net published a write-up shortly after disclosure. Aisle.com later referenced this CVE in a broader report identifying 38 critical security vulnerabilities in healthcare software used by 100,000 providers, highlighting the patient safety implications of EHR security flaws (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."