CVE-2026-33299: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-33299 is a stored cross-site scripting (XSS) vulnerability in OpenEMR's Eye Exam form functionality, affecting all versions prior to 8.0.0.2. Authenticated users with the Notes - my encounters role can inject arbitrary JavaScript payloads into Eye Exam form fields (e.g., the HPI field), which are then executed in the browsers of any other user with the same role who views the affected patient encounter page, visit history, or printed report. The vulnerability was published on March 19, 2026, with a fix released in version 8.0.0.2. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically in interface/forms/eye_mag/report.php, where form field values such as codetext, plan, and ORDER_DETAILS were echoed directly into HTML output without escaping. The fix applied in commit dccc962 wraps these outputs with OpenEMR's text() sanitization function to HTML-encode user-supplied values before rendering. An attacker with the Notes - my encounters role submits a malicious payload (e.g., <img src=x onerror=alert(document.cookie)>) into the HPI field of an Eye Exam form; the script is stored in the database and executes automatically whenever any eligible user views the encounter, visit history, or generates a print report (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of other authenticated users — including Administrators, Clinicians, and Physicians — who view the affected patient encounter or visit history. This enables session hijacking, credential theft, unauthorized actions performed on behalf of victim users (including privilege escalation by targeting administrator accounts), and exfiltration of sensitive patient health records. The stored nature of the XSS means the payload executes automatically and persistently without further attacker interaction (GitHub Advisory).

Exploitability

A proof-of-concept exploit with detailed step-by-step reproduction instructions and a specific payload (<img src=x onerror=alert(document.cookie)>) is publicly documented in the GitHub Security Advisory. Feedly's threat intelligence classifies the PoC confidence as high, noting nine numbered reproduction steps with precise navigation paths within the OpenEMR UI. There is no current evidence of in-the-wild exploitation, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.174%, reflecting low but non-zero exploitation probability (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify an OpenEMR instance running a version prior to 8.0.0.2. Confirm access to an account with the Notes - my encounters role (e.g., a default Clinician account).
  2. Authenticate: Log in to the OpenEMR instance with the attacker-controlled clinician account.
  3. Select or create a patient: Navigate to Patient > New/Search to create or select an existing patient record.
  4. Open or create a visit: Navigate to Patient > Visits > Create Visit or select an existing visit.
  5. Open the Eye Exam form: On the Encounter tab, click Clinical > Eye Exam.
  6. Inject the payload: In the HPI > HPI field, enter a malicious XSS payload such as <img src=x onerror=alert(document.cookie)> (or a more sophisticated payload for session theft or data exfiltration).
  7. Save the form: Click Save to persist the payload in the database.
  8. Trigger execution — Print Report: Click File > Print Report; the XSS fires immediately in the attacker's own browser, confirming the injection.
  9. Trigger execution — Victim view: When any other user with the Notes - my encounters role views the Encounter tab or navigates to Patient > Visits > Visit History and hovers over the affected form entry, the malicious script executes in their browser, enabling session hijacking or further exploitation (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from a clinician or physician browser session to attacker-controlled domains (e.g., for cookie exfiltration via document.cookie in XSS payloads).
  • Logs: OpenEMR access logs showing POST requests to Eye Exam form submission endpoints (e.g., /interface/forms/eye_mag/save.php) containing HTML/JavaScript tags in form field parameters; repeated access to report.php for the same encounter by multiple users shortly after a form submission.
  • File System: No direct file system artifacts expected for this stored XSS; however, review database entries in form_eye_mag tables for fields containing <script>, onerror=, javascript:, or other HTML event handler patterns.
  • Application: Unexpected JavaScript alert dialogs or browser console errors appearing when clinicians, physicians, or administrators view patient encounter pages or visit history; anomalous session activity (e.g., session tokens used from unexpected IP addresses after viewing an encounter) (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0.2 or later, which escapes user-supplied form values throughout the Eye Exam report template using the text() function (Patch Commit). As a temporary workaround prior to patching, implement a strict Content Security Policy (CSP) header to restrict inline script execution, and limit the Notes - my encounters role to only highly trusted users. Administrators should also audit existing Eye Exam form entries in the database for stored malicious payloads and sanitize them manually if found (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher lassiiiiii and remediated by kojiromike (Michael A. Smith of OpenCoreEMR Inc.), with the advisory published on March 18, 2026. The advisory notes that the same root cause — unescaped Eye Exam form output — also underlies two related advisories: GHSA-5pc3-2crw-96rv (OOB SSRF via mPDF) and GHSA-v9v3-q973-xp2h / CVE-2026-33301 (arbitrary file read via mPDF), and the single patch addresses all three vectors. Coverage was picked up by security aggregators including infinitsec.net and VulDB shortly after disclosure (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management