
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33915 is a missing authorization vulnerability in OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. Five insurance company REST API routes in apis/routes/_rest_routes_standard.inc.php are missing the RestConfig::request_authorization_check() call required by all other data-modifying routes, allowing any authenticated API user to create or modify insurance company records without administrative ACL permissions. All versions prior to 8.0.0.3 are affected; version 8.0.0.3 patches the issue. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Red Hat CVE). It was published on March 25–26, 2026.
The root cause is CWE-862 (Missing Authorization): five insurance company API route handlers in apis/routes/_rest_routes_standard.inc.php (lines 462–489 in the pre-patch code) omit the RestConfig::request_authorization_check() call present in analogous administrative routes such as the facility endpoints. The affected routes are GET /api/insurance_company, GET /api/insurance_company/:iid, GET /api/insurance_type, POST /api/insurance_company, and PUT /api/insurance_company/:iid. An attacker with any valid authenticated API session — regardless of their ACL role — can send standard HTTP GET, POST, or PUT requests to these endpoints to read, create, or modify insurance company records (name, address, CMS ID, X12 receiver ID). The fix adds RestConfig::request_authorization_check($request, "acct", "bill") for read routes and RestConfig::request_authorization_check($request, "acct", "bill", 'write') for write routes (GitHub Advisory, Patch Commit).
Successful exploitation allows a low-privileged authenticated API user — such as a clinician with only patient demographics access — to create or modify insurance company records, which is an administrative function. This can corrupt billing workflows, disrupt insurance claim processing, and tamper with CMS IDs and X12 receiver IDs used in healthcare billing. While availability is not directly impacted, the integrity of administrative insurance data and the confidentiality of insurance company records are both at risk, with potential downstream effects on medical billing and patient insurance management (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The EPSS score is approximately 0.02%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid API credentials, limiting the attack surface to authenticated users, but no special privileges beyond a basic API account are needed.
/api/insurance_company with a JSON body containing insurance company fields (e.g., name, address, cms_id, x12_receiver_id) without any administrative ACL being enforced./api/insurance_company/:iid with the target insurance company ID and desired data changes./api/insurance_company or /api/insurance_company/:iid to enumerate existing insurance company records, which also lack authorization checks./api/insurance_company or /api/insurance_company/:iid from non-administrative user accounts; GET requests to /api/insurance_type from accounts without billing roles.acct/bill ACL permissions; repeated or bulk modifications to insurance company records in audit logs.Upgrade all OpenEMR installations to version 8.0.0.3 or later, which adds the required RestConfig::request_authorization_check() calls to all five affected insurance company API routes (OpenEMR Release, Patch Commit). Until patching is complete, restrict API access to trusted users only and implement network-level controls (e.g., firewall rules, API gateway policies) to limit exposure of the /api/insurance_company and /api/insurance_type endpoints. Monitor audit logs for unauthorized modifications to insurance company records and ensure API users are assigned the minimum necessary roles.
The vulnerability was credited to researcher kojiromike and disclosed via GitHub Security Advisories on March 25, 2026 (GitHub Advisory). Red Hat tracked the issue in their CVE database (Red Hat CVE). No significant broader media coverage or notable social media reactions have been identified beyond standard CVE aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."