
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32127 is a SQL injection vulnerability in OpenEMR's ajax graphs library (library/ajax/graphs.php) that can be exploited by authenticated attackers to execute arbitrary SQL commands against the underlying database. It affects all OpenEMR versions prior to 8.0.0.1 and was published on March 11, 2026. The vulnerability was discovered by researcher Christophe SUBLET of Esisar (CyberSkills, Orion project) and fixed in version 8.0.0.1. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In library/ajax/graphs.php, the name parameter from a POST request is retrieved via $name = trim((string) $_POST['name']) and then directly concatenated into SQL query strings using add_escape_custom($name) as a column alias — a context where parameterized queries are not applied, allowing the alias position to be abused for injection. Specifically, the vulnerable code appears at lines 29, 76, and 185 of graphs.php, where the unsanitized $name value is embedded into SELECT statements. Attackers can leverage time-based blind injection (e.g., date,SLEEP(1) FROM ...) and boolean-based UNION SELECT techniques to extract data from arbitrary tables, including the users_secure table containing hashed credentials (GitHub Advisory).
Successful exploitation allows any authenticated user to read, modify, or delete data across the entire OpenEMR database, including sensitive protected health information (PHI) and patient records. Demonstrated impact includes extraction of administrator credentials (bcrypt password hashes) from the users_secure table, which could enable full account takeover and further privilege escalation. In some configurations, database-level access may also facilitate server-side code execution, potentially leading to complete system compromise (GitHub Advisory).
Multiple public proof-of-concept exploits are available, including a Python-based exploit script (exploit.py) and detailed curl command sequences demonstrating time-based and boolean-based SQL injection against live OpenEMR 8.0.0 instances (PoC GitHub, GitHub Advisory). The EPSS score is approximately 0.03% (low probability of near-term exploitation), and there is no confirmed evidence of in-the-wild exploitation at this time. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported.
OpenEMR=<session_id>) and CSRF token (csrf_token_form).http://<target>/library/ajax/graphs.php, which accepts POST requests with name, table, and csrf_token_form parameters.name value (e.g., name=payload"injection&table=LBF) to confirm SQL error output, verifying the injection point:curl -k -b "OpenEMR=<session>" --data 'csrf_token_form=<token>&name=payload"injection&table=LBF' 'http://<target>/library/ajax/graphs.php'SLEEP-based payload to observe response delays:curl -k -b "OpenEMR=<session>" --data 'csrf_token_form=<token>&name=date,SLEEP(5)%20FROM%20(SELECT%201%20AS%20field_value)%20AS%20ld%20UNION%20SELECT%20ld.field_value%20AS%20date&table=LBF' 'http://<target>/library/ajax/graphs.php'users_secure) using the provided exploit3.py script:python3 exploit3.py <target_ip> <session_cookie> <csrf_token> users_secure --columns username passwordusers_secure, then attempt offline cracking to recover plaintext credentials for administrative account takeover (GitHub Advisory, PoC GitHub)./library/ajax/graphs.php with name parameter values containing SQL keywords (SLEEP, UNION, SELECT, FROM, NULL) or URL-encoded equivalents; abnormally slow responses to requests targeting this endpoint (indicative of time-based injection)./library/ajax/graphs.php with large or encoded name parameter values; OpenEMR application logs containing SQL error messages referencing graphs.php at lines 74, 76, or 185 with unexpected SQL syntax errors.SLEEP(), UNION ALL SELECT, or queries referencing users_secure table columns (username, password) originating from the OpenEMR application context.exploit3.py) from non-standard locations on systems with access to the OpenEMR instance (GitHub Advisory).The primary remediation is to upgrade OpenEMR to version 8.0.0.1 or later, which addresses the insufficient input validation in library/ajax/graphs.php (GitHub Advisory). As interim mitigations, administrators should implement Web Application Firewall (WAF) rules to detect and block SQL injection patterns targeting the graphs.php endpoint, and restrict access to the ajax graphs functionality to only authorized roles. Database activity monitoring should be enabled to alert on anomalous query patterns such as SLEEP() calls or unexpected UNION SELECT statements originating from the application.
The vulnerability received coverage from The Hacker Wire, which published an article on the SQL injection issue shortly after disclosure (The Hacker Wire). The advisory was also noted on Mastodon by The Hacker Wire's account. Community interest was moderate, with the CVE appearing across multiple vulnerability tracking platforms (VulDB, CVEFeed, CIRCL, ENISA EUVD) within hours of publication. No major vendor statements beyond the official GitHub Security Advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."