CVE-2026-32126: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-32126 is an authorization bypass vulnerability in OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. An inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be applied only to controllers that already self-enforce authorization (review, log), while leaving six other CDR controllers (alerts, ajax, edit, add, detail, browse) accessible to any authenticated user. All versions prior to 8.0.0.1 are affected; the vulnerability was introduced in commit cd290ffd68 (October 2024) and disclosed on March 11, 2026. It carries a CVSS v3.1 base score of 8.1 (High) per NVD, or 7.1 (High) per the GitHub advisory (GitHub Advisory).

Technical details

The root cause is a logic inversion bug (CWE-862: Missing Authorization) in src/ClinicalDecisionRules/Interface/ControllerRouter.php. The shouldSkipAdminAcl() method returns true for the review and log controllers (which self-protect), but the route() method uses this return value directly in the condition if ($this->shouldSkipAdminAcl($controller) && !AclMain::aclCheckCore('admin', 'super')) — meaning the ACL gate fires only when shouldSkipAdminAcl is true (i.e., for already-protected controllers), and short-circuits to no check for all other controllers. An attacker needs only a valid authenticated session (any role) and can exploit the vulnerability over the network with no user interaction by sending crafted HTTP requests directly to /interface/super/rules/index.php. The advisory includes concrete PoC steps with specific HTTP requests and curl commands (GitHub Advisory).

Impact

Any authenticated OpenEMR user — regardless of role — can perform administrator-only operations on the Clinical Decision Rules (CDR) subsystem. The most critical impact is the ability to silently suppress clinical decision support alerts system-wide (e.g., drug interaction warnings, preventive care reminders), which carries direct patient safety implications. Additionally, attackers can delete or modify clinical plans and edit rule configurations, degrading CDS workflows for an entire medical practice. There is no confidentiality impact, but integrity and availability of clinical decision support data are severely affected (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub security advisory, including step-by-step HTTP requests and curl commands demonstrating the authorization bypass on a real OpenEMR instance (GitHub Advisory). As of the time of reporting, there is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.036%, reflecting low but non-zero exploitation probability. Exploitation requires only a valid authenticated session, making it accessible to any low-privileged user with an account on the system.

Exploitation steps

  1. Reconnaissance: Identify an OpenEMR instance running a version prior to 8.0.0.1. The CDR management page at /interface/super/rules/ is hidden from non-admin users in the UI, but direct URL access is not blocked.
  2. Authenticate: Log in to OpenEMR with any valid user account (e.g., a front-office or clinical staff role with default permissions).
  3. Suppress clinical alerts (integrity attack): Send a POST request to the unprotected alerts!submitactmgr action with parameters to disable alert flags for a target clinical rule:
    POST /interface/super/rules/index.php?action=alerts!submitactmgr
    Content-Type: application/x-www-form-urlencoded
    id[0]=rule_dm_a1c_cqm&active[0]=off&passive[0]=off&reminder[0]=off&access_control[0]=
    The server responds with a 302 redirect, indicating success.
  4. Delete clinical plans (availability attack): Send a GET request to the unprotected ajax!deletePlan action using a valid session cookie:
    curl -b "OpenEMR=<session_cookie>" \
      "https://<target>/interface/super/rules/index.php?action=ajax!deletePlan&plan_id=<plan_id>"
    The targeted plan is deleted from clinical_plans, list_options, and clinical_plans_rules tables.
  5. Verify impact: Query the database to confirm that alert flags are now set to 0 or that the clinical plan no longer exists, confirming successful exploitation (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected POST or GET requests to /interface/super/rules/index.php originating from non-administrative user sessions; requests with parameters such as action=alerts!submitactmgr, action=ajax!deletePlan, action=ajax!togglePlanStatus, or action=ajax!commitChanges.
  • Logs: OpenEMR access logs showing non-admin users accessing /interface/super/rules/index.php with write-action parameters; 302 redirect responses to CDR management endpoints from low-privileged accounts.
  • Database: Unexpected changes to active_alert_flag, passive_alert_flag, patient_reminder_flag, or access_control columns in the clinical_rules table (especially where pid = 0, indicating system-wide changes); missing or modified records in clinical_plans, list_options, or clinical_plans_rules tables without corresponding admin activity (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0.1 or later, which contains the fix for the inverted boolean condition in ControllerRouter::route(). No configuration-based workaround is available, as the flaw is in application logic. As an interim measure, administrators should restrict network access to the /interface/super/rules/ path to admin-only IP ranges or require additional authentication at the web server level. After patching, review access logs and audit the clinical_rules, clinical_plans, and related tables for unauthorized modifications made by non-administrative users prior to the upgrade (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher pavelkohout396 and analyzed by simecek, with the advisory published by kojiromike on the OpenEMR GitHub repository. Security blog Infinitsec.net published a write-up shortly after disclosure. Aisle.com later referenced this CVE in a broader report identifying 38 critical security vulnerabilities in healthcare software used by 100,000 providers, highlighting the patient safety implications of EHR security flaws (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management