CVE-2026-33915: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-33915 is a missing authorization vulnerability in OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. Five insurance company REST API routes in apis/routes/_rest_routes_standard.inc.php are missing the RestConfig::request_authorization_check() call required by all other data-modifying routes, allowing any authenticated API user to create or modify insurance company records without administrative ACL permissions. All versions prior to 8.0.0.3 are affected; version 8.0.0.3 patches the issue. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Red Hat CVE). It was published on March 25–26, 2026.

Technical details

The root cause is CWE-862 (Missing Authorization): five insurance company API route handlers in apis/routes/_rest_routes_standard.inc.php (lines 462–489 in the pre-patch code) omit the RestConfig::request_authorization_check() call present in analogous administrative routes such as the facility endpoints. The affected routes are GET /api/insurance_company, GET /api/insurance_company/:iid, GET /api/insurance_type, POST /api/insurance_company, and PUT /api/insurance_company/:iid. An attacker with any valid authenticated API session — regardless of their ACL role — can send standard HTTP GET, POST, or PUT requests to these endpoints to read, create, or modify insurance company records (name, address, CMS ID, X12 receiver ID). The fix adds RestConfig::request_authorization_check($request, "acct", "bill") for read routes and RestConfig::request_authorization_check($request, "acct", "bill", 'write') for write routes (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows a low-privileged authenticated API user — such as a clinician with only patient demographics access — to create or modify insurance company records, which is an administrative function. This can corrupt billing workflows, disrupt insurance claim processing, and tamper with CMS IDs and X12 receiver IDs used in healthcare billing. While availability is not directly impacted, the integrity of administrative insurance data and the confidentiality of insurance company records are both at risk, with potential downstream effects on medical billing and patient insurance management (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The EPSS score is approximately 0.02%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires valid API credentials, limiting the attack surface to authenticated users, but no special privileges beyond a basic API account are needed.

Exploitation steps

  1. Obtain API credentials: Acquire any valid OpenEMR API user account — even a low-privileged clinician account with only patient demographics access is sufficient.
  2. Authenticate to the API: Use the OpenEMR OAuth2 or standard API authentication flow to obtain a valid API token or session.
  3. Target vulnerable endpoints: Send an HTTP POST request to /api/insurance_company with a JSON body containing insurance company fields (e.g., name, address, cms_id, x12_receiver_id) without any administrative ACL being enforced.
  4. Create or modify records: To modify an existing record, send an HTTP PUT request to /api/insurance_company/:iid with the target insurance company ID and desired data changes.
  5. Read insurance data: Optionally, send GET requests to /api/insurance_company or /api/insurance_company/:iid to enumerate existing insurance company records, which also lack authorization checks.
  6. Impact billing workflows: Manipulated insurance company records (e.g., altered CMS IDs or X12 receiver IDs) can disrupt insurance claim submissions and billing processes (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Network: Unexpected POST or PUT requests to /api/insurance_company or /api/insurance_company/:iid from non-administrative user accounts; GET requests to /api/insurance_type from accounts without billing roles.
  • Logs: OpenEMR API access logs showing authenticated requests to insurance company endpoints from user accounts that do not hold acct/bill ACL permissions; repeated or bulk modifications to insurance company records in audit logs.
  • Application Data: Unexpected creation or modification of insurance company records (name, address, CMS ID, X12 receiver ID) not initiated by administrative staff; discrepancies in billing-related insurance data compared to known-good baselines.

Mitigation and workarounds

Upgrade all OpenEMR installations to version 8.0.0.3 or later, which adds the required RestConfig::request_authorization_check() calls to all five affected insurance company API routes (OpenEMR Release, Patch Commit). Until patching is complete, restrict API access to trusted users only and implement network-level controls (e.g., firewall rules, API gateway policies) to limit exposure of the /api/insurance_company and /api/insurance_type endpoints. Monitor audit logs for unauthorized modifications to insurance company records and ensure API users are assigned the minimum necessary roles.

Community reactions

The vulnerability was credited to researcher kojiromike and disclosed via GitHub Security Advisories on March 25, 2026 (GitHub Advisory). Red Hat tracked the issue in their CVE database (Red Hat CVE). No significant broader media coverage or notable social media reactions have been identified beyond standard CVE aggregator coverage.

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management