
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33304 is an authorization bypass vulnerability in OpenEMR's dated reminders log that allows any authenticated non-admin user to view reminder messages belonging to other users, including associated patient names and free-text message content. It affects all OpenEMR versions prior to 8.0.0.2 and was disclosed on March 19, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The root cause is a flawed server-side authorization guard in interface/main/dated_reminders/dated_reminders_log.php (CWE-639: Authorization Bypass Through User-Controlled Key; CWE-862: Missing Authorization). The guard was designed to restrict non-admin users to their own reminders, but it only activated when both the sentBy[] and sentTo[] GET parameters were absent — if a user explicitly supplied either parameter, the AND condition evaluated to false and no restriction was applied. The downstream function logRemindersArray() in library/dated_reminder_functions.php then consumed these user-supplied parameters directly to build SQL WHERE clauses with no further authorization check, and patient names were resolved via a separate per-row query against patient_data — also unchecked. The UI dropdown limiting non-admin users to "Myself" was a purely client-side control providing no security (GitHub Advisory, Patch Commit).
Successful exploitation exposes Protected Health Information (PHI) in a healthcare context, including patient names from the patient_data table and free-text reminder message content belonging to any user in the system. An attacker can enumerate reminders across all users by iterating over sequential integer user IDs. The exposure is read-only — no modification of reminders is possible through this vector — but the confidentiality impact is rated High given the sensitivity of the data involved (GitHub Advisory).
A proof-of-concept exploit with step-by-step instructions is publicly available in the GitHub Security Advisory, demonstrating exploitation via a simple crafted GET request requiring only a valid CSRF token and a low-privileged authenticated session. The EPSS score is approximately 0.028% (0.000280), indicating low predicted exploitation probability in the near term. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (GitHub Advisory).
dated_reminders_log.php. Inspect the page source to extract the csrf_token_form value.curl, issue a request such as:GET /interface/main/dated_reminders/dated_reminders_log.php?csrf_token_form=<token>&sentTo[]=5Replace 5 with any target user's ID.sentBy[]=<id> similarly exposes all reminders authored by that user across all recipients (GitHub Advisory)./interface/main/dated_reminders/dated_reminders_log.php with sentTo[] or sentBy[] parameters containing user IDs other than the authenticated user's own ID; sequential enumeration of integer user ID values in these parameters.Upgrade OpenEMR to version 8.0.0.2 or later, which fixes the issue by unconditionally overriding the sentBy[] and sentTo[] parameters to the current authenticated user's ID for all non-admin users, regardless of user input. The patch is available at commit 21dee7658a5f3b18c5750e3fae7324e875c1703a. As an interim measure prior to patching, restrict network access to the OpenEMR instance to trusted personnel only, and review web server access logs for signs of unauthorized enumeration of the dated reminders log endpoint (Patch Commit, GitHub Advisory).
The vulnerability was reported by researchers pavelkohout396, stanislavfortaisle, and simecek, and was remediated by OpenEMR maintainer kojiromike. Aisle published a blog post noting this CVE as part of a broader discovery of 38 security vulnerabilities in healthcare software used by 100,000 providers, highlighting the systemic security risks in widely deployed EHR platforms (Aisle Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."