CVE-2026-32127: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-32127 is a SQL injection vulnerability in OpenEMR's ajax graphs library (library/ajax/graphs.php) that can be exploited by authenticated attackers to execute arbitrary SQL commands against the underlying database. It affects all OpenEMR versions prior to 8.0.0.1 and was published on March 11, 2026. The vulnerability was discovered by researcher Christophe SUBLET of Esisar (CyberSkills, Orion project) and fixed in version 8.0.0.1. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In library/ajax/graphs.php, the name parameter from a POST request is retrieved via $name = trim((string) $_POST['name']) and then directly concatenated into SQL query strings using add_escape_custom($name) as a column alias — a context where parameterized queries are not applied, allowing the alias position to be abused for injection. Specifically, the vulnerable code appears at lines 29, 76, and 185 of graphs.php, where the unsanitized $name value is embedded into SELECT statements. Attackers can leverage time-based blind injection (e.g., date,SLEEP(1) FROM ...) and boolean-based UNION SELECT techniques to extract data from arbitrary tables, including the users_secure table containing hashed credentials (GitHub Advisory).

Impact

Successful exploitation allows any authenticated user to read, modify, or delete data across the entire OpenEMR database, including sensitive protected health information (PHI) and patient records. Demonstrated impact includes extraction of administrator credentials (bcrypt password hashes) from the users_secure table, which could enable full account takeover and further privilege escalation. In some configurations, database-level access may also facilitate server-side code execution, potentially leading to complete system compromise (GitHub Advisory).

Exploitability

Multiple public proof-of-concept exploits are available, including a Python-based exploit script (exploit.py) and detailed curl command sequences demonstrating time-based and boolean-based SQL injection against live OpenEMR 8.0.0 instances (PoC GitHub, GitHub Advisory). The EPSS score is approximately 0.03% (low probability of near-term exploitation), and there is no confirmed evidence of in-the-wild exploitation at this time. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported.

Exploitation steps

  1. Authentication: Obtain valid credentials for any OpenEMR user account (low-privilege access is sufficient) and log in to retrieve a valid session cookie (e.g., OpenEMR=<session_id>) and CSRF token (csrf_token_form).
  2. Identify target endpoint: Locate the vulnerable endpoint at http://<target>/library/ajax/graphs.php, which accepts POST requests with name, table, and csrf_token_form parameters.
  3. Confirm injection: Send a crafted POST request with a malformed name value (e.g., name=payload"injection&table=LBF) to confirm SQL error output, verifying the injection point:
    curl -k -b "OpenEMR=<session>" --data 'csrf_token_form=<token>&name=payload"injection&table=LBF' 'http://<target>/library/ajax/graphs.php'
  4. Time-based blind injection: Confirm exploitability using a SLEEP-based payload to observe response delays:
    curl -k -b "OpenEMR=<session>" --data 'csrf_token_form=<token>&name=date,SLEEP(5)%20FROM%20(SELECT%201%20AS%20field_value)%20AS%20ld%20UNION%20SELECT%20ld.field_value%20AS%20date&table=LBF' 'http://<target>/library/ajax/graphs.php'
  5. Boolean-based data extraction: Use UNION SELECT payloads to extract data character by character from target tables (e.g., users_secure) using the provided exploit3.py script:
    python3 exploit3.py <target_ip> <session_cookie> <csrf_token> users_secure --columns username password
  6. Credential recovery: Extract bcrypt-hashed passwords from users_secure, then attempt offline cracking to recover plaintext credentials for administrative account takeover (GitHub Advisory, PoC GitHub).

Indicators of compromise

  • Network: Unusual HTTP POST requests to /library/ajax/graphs.php with name parameter values containing SQL keywords (SLEEP, UNION, SELECT, FROM, NULL) or URL-encoded equivalents; abnormally slow responses to requests targeting this endpoint (indicative of time-based injection).
  • Logs: Web server access logs showing repeated POST requests to /library/ajax/graphs.php with large or encoded name parameter values; OpenEMR application logs containing SQL error messages referencing graphs.php at lines 74, 76, or 185 with unexpected SQL syntax errors.
  • Database: Unusual or unexpected queries in the database query log involving SLEEP(), UNION ALL SELECT, or queries referencing users_secure table columns (username, password) originating from the OpenEMR application context.
  • Process: Execution of Python scripts (e.g., exploit3.py) from non-standard locations on systems with access to the OpenEMR instance (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade OpenEMR to version 8.0.0.1 or later, which addresses the insufficient input validation in library/ajax/graphs.php (GitHub Advisory). As interim mitigations, administrators should implement Web Application Firewall (WAF) rules to detect and block SQL injection patterns targeting the graphs.php endpoint, and restrict access to the ajax graphs functionality to only authorized roles. Database activity monitoring should be enabled to alert on anomalous query patterns such as SLEEP() calls or unexpected UNION SELECT statements originating from the application.

Community reactions

The vulnerability received coverage from The Hacker Wire, which published an article on the SQL injection issue shortly after disclosure (The Hacker Wire). The advisory was also noted on Mastodon by The Hacker Wire's account. Community interest was moderate, with the CVE appearing across multiple vulnerability tracking platforms (VulDB, CVEFeed, CIRCL, ENISA EUVD) within hours of publication. No major vendor statements beyond the official GitHub Security Advisory have been identified.

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management