CVE-2026-33348: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-33348 is a stored cross-site scripting (XSS) vulnerability in OpenEMR's Eye Exam form, specifically in the display of the $CHRONIC2 and $CHRONIC3 fields within patient encounter records. It affects all OpenEMR versions prior to 8.0.0.3 and was disclosed on March 25, 2026, with a patch released the same day. The vulnerability is classified as High severity with a CVSS v3.1 base score of 8.7 per the GitHub Security Advisory, though NVD records a score of 5.4 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is improper neutralization of user-controlled input before it is rendered in web page output (CWE-79). In interface/forms/eye_mag/report.php, the variables $CHRONIC2 and $CHRONIC3 were echoed directly into the HTML response without sanitization (e.g., echo " " . $CHRONIC2 . "";), allowing arbitrary JavaScript to be stored and later executed in victims' browsers. The fix applied the OpenEMR text() escaping function to these variables in report.php, a_issue.php, and SpectacleRx.php. Exploitation requires an authenticated attacker with the Notes - my encounters role, and the payload executes automatically when any user with the same role views the affected encounter page, prints the report, or hovers over the visit history entry (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated attacker to inject persistent JavaScript that executes in the browsers of all users with the Notes - my encounters role who view the affected patient encounter pages, print reports, or visit history. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of higher-privileged users (e.g., administrators), and exfiltration of sensitive patient health records. In a default OpenEMR installation, affected groups include Administrators, Clinicians, and Physicians, making privilege escalation from a low-privilege clinician account to an administrator a realistic attack scenario (GitHub Advisory).

Exploitability

A proof-of-concept with detailed step-by-step reproduction instructions and example XSS payloads (e.g., <img src="x" onerror="alert('CHRONIC2 '+document.domain)">) is publicly available in the GitHub Security Advisory. The EPSS score is approximately 0.031% (0.000310), indicating low automated exploitation probability at this time. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of disclosure. No threat actor attribution has been reported (GitHub Advisory, Feedly).

Exploitation steps

  1. Gain access: Log in to the OpenEMR instance with an account that has the Notes - my encounters role enabled (e.g., a default Clinicians group member such as clinician1).
  2. Select or create a patient: Navigate to Patient > New/Search to select an existing patient or create a new one.
  3. Open or create a visit: Navigate to Patient > Visits > Create Visit or select an existing visit via Patient > Visits > Visit History.
  4. Access the Eye Exam form: On the Encounter tab, click Clinical > Eye Exam.
  5. Fill in required fields: Enter any value in the HPI > CC1 > Chief Complaint 1 field and any value in the first Chronic Problems input.
  6. Inject XSS payload: In the second Chronic Problems input ($CHRONIC2), enter a malicious payload such as <img src="x" onerror="alert('CHRONIC2 '+document.domain)">, and optionally a similar payload in the third input ($CHRONIC3).
  7. Save the form: Click Save to persist the malicious payload in the database.
  8. Trigger execution: The XSS fires when any user with the role:
    • Clicks File > Print Report on the encounter.
    • Views the Encounter tab for the affected visit.
    • Hovers over the previous form entry in Patient > Visits > Visit History under the Reason/Form column.
  9. Achieve objective: Replace the alert() payload with a script that exfiltrates session cookies, performs CSRF actions, or escalates privileges by targeting an administrator who views the encounter (GitHub Advisory).

Indicators of compromise

  • Logs: OpenEMR application or web server access logs showing POST requests to the Eye Exam form endpoint (/interface/forms/eye_mag/) containing HTML/JavaScript tags (e.g., <script>, <img, onerror=) in form field parameters.
  • Database: Entries in the Eye Exam form table where CHRONIC2 or CHRONIC3 fields contain HTML tags, JavaScript event handlers, or encoded script content.
  • Network: Outbound HTTP requests from the OpenEMR server or client browsers to unexpected external domains shortly after a user views an Eye Exam encounter — potentially indicating data exfiltration via XSS payload.
  • Logs: Unusual session activity for administrator or high-privilege accounts (e.g., unexpected configuration changes, new user creation) that correlate with viewing affected patient encounter pages (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0.3 or later, which contains the patch applying proper HTML escaping via the text() function to the affected $CHRONIC2 and $CHRONIC3 variables in report.php, a_issue.php, and SpectacleRx.php (Patch Commit, Release Notes). As interim mitigations, restrict the Notes - my encounters role to only trusted users, implement a strict Content Security Policy (CSP) header to limit the impact of any XSS, and monitor form submissions for entries containing script tags or JavaScript event handlers (Feedly).

Community reactions

The vulnerability was covered by The Hacker Wire shortly after disclosure, and social media posts appeared on Mastodon and Bluesky referencing the CVE. The advisory was published by the OpenEMR project maintainers on GitHub and credited researcher lassiiiiii for the report and kojiromike for the remediation. No major vendor statements beyond the OpenEMR advisory or significant analyst commentary have been identified (The Hacker Wire, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management