CVE-2026-33917: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-33917 is a SQL injection vulnerability in the CAMOS form's ajax_save page of OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. It affects all OpenEMR versions prior to 8.0.0.3 and can be exploited by authenticated attackers with low privileges over the network. The vulnerability was disclosed on March 25–26, 2026, and patched in version 8.0.0.3 released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). User-supplied input from the content POST parameter in ajax_save.php is passed to the process_commands() function in content_parser.php, where it is extracted via regex and directly concatenated into SQL queries using add_escape_custom() — a function insufficient to prevent injection in this numeric context. Specifically, the $days variable extracted from patterns like /*date_add::...*/ and /*date_sub::...*/ is inserted into DATE_ADD/DATE_SUB SQL interval expressions without integer casting, and the same flaw exists in the addAppt() function. The fix applied integer casting (int) $days to neutralize the injection (GitHub Advisory, Patch Commit). Affected files include interface/forms/CAMOS/content_parser.php (lines 21, 127, 137, 186) and interface/forms/CAMOS/ajax_save.php (line 28).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary SQL queries against the underlying MariaDB/MySQL database, enabling extraction of sensitive patient health information, user credentials (including bcrypt password hashes from the users_secure table), and other protected health data. Attackers can also modify or delete medical records, potentially compromising data integrity and availability. Given that OpenEMR handles protected health information (PHI), exploitation could result in HIPAA violations and significant regulatory consequences (GitHub Advisory, Feedly).

Exploitability

Public proof-of-concept (PoC) exploit code is available on GitHub, including a Python script (exploit2.py) that performs time-based blind SQL injection to extract data from the users_secure table, and curl-based payloads demonstrating boolean-based blind injection (PoC Repository). The EPSS score is approximately 0.029% (low), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of reporting (Feedly). No threat actor attribution has been identified. Exploitation requires only a valid low-privilege authenticated session, making it accessible to any user with an account on the system.

Exploitation steps

  1. Obtain Authentication: Log in to the target OpenEMR instance with any low-privilege user account to obtain a valid session cookie (e.g., OpenEMR=<session_id>) and a CSRF token.
  2. Identify the vulnerable endpoint: Target http://<target>/interface/forms/CAMOS/ajax_save.php via HTTP POST.
  3. Craft the injection payload: Embed a SQL injection payload within the content parameter using the CAMOS comment syntax, e.g., content=/*date_add::<SQL_PAYLOAD>*/. The $days value extracted from this pattern is concatenated unsanitized into a DATE_ADD SQL interval expression.
  4. Boolean-based blind injection: Send payloads that alter query behavior based on true/false conditions (e.g., WHERE 1=1 vs WHERE 1=0) and observe differing server responses to infer data character by character.
  5. Time-based blind injection: Use SLEEP() within the injected interval to confirm injection and enumerate data based on response timing.
  6. Extract sensitive data: Use the provided Python exploit script (exploit2.py) to automate extraction of usernames and bcrypt password hashes from the users_secure table: python3 exploit2.py <host> <session_cookie> <csrf_token> users_secure --columns username password.
  7. Crack credentials or pivot: Use extracted password hashes for offline cracking or leverage database access for further lateral movement within the application (GitHub Advisory, PoC Repository).

Indicators of compromise

  • Network: Unusual HTTP POST requests to /interface/forms/CAMOS/ajax_save.php containing URL-encoded SQL keywords (SLEEP, UNION, SELECT, CHAR, DATE_ADD, WHERE) in the content parameter; repeated requests with slight payload variations indicative of blind injection enumeration.
  • Logs: OpenEMR application logs showing SQL Statement failed on preparation or OpenEMR SQL Escaping ERROR messages originating from content_parser.php or ajax_save.php; web server access logs with POST requests to ajax_save.php containing %2F%2Adate_add%3A%3A (URL-encoded /*date_add::) patterns.
  • Database: Unexpected or anomalous queries in the MariaDB/MySQL general query log involving SLEEP(), UNION SELECT, or CHAR() functions in the context of form_encounter or users_secure tables.
  • Process/Behavior: Unusual response time delays (5+ seconds) from the OpenEMR web server on requests to ajax_save.php, consistent with time-based blind SQL injection probing (GitHub Advisory, PoC Repository).

Mitigation and workarounds

The primary remediation is to upgrade OpenEMR to version 8.0.0.3 or later, which applies integer casting (int) $days to the vulnerable SQL interval parameters in content_parser.php and addAppt(), eliminating the injection (Patch Commit, Release Notes). As an interim measure, restrict network access to the CAMOS form endpoint (/interface/forms/CAMOS/ajax_save.php) via firewall or web application firewall (WAF) rules, and limit user privileges to the minimum necessary. Monitor database activity for suspicious SQL injection patterns as described in the IOCs section (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher Christophe SUBLET (ChrisSub08) from Esisar as part of the CyberSkills/Orion project, and credited in the official GitHub Security Advisory (GitHub Advisory). Coverage appeared on The Hacker Wire and was noted on Mastodon and Bluesky shortly after disclosure (Feedly). The vulnerability was also registered with ENISA's European Vulnerability Database (EUVD-2026-16032). No major vendor statements beyond the OpenEMR security advisory have been identified.

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management