
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33917 is a SQL injection vulnerability in the CAMOS form's ajax_save page of OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. It affects all OpenEMR versions prior to 8.0.0.3 and can be exploited by authenticated attackers with low privileges over the network. The vulnerability was disclosed on March 25–26, 2026, and patched in version 8.0.0.3 released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Feedly).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). User-supplied input from the content POST parameter in ajax_save.php is passed to the process_commands() function in content_parser.php, where it is extracted via regex and directly concatenated into SQL queries using add_escape_custom() — a function insufficient to prevent injection in this numeric context. Specifically, the $days variable extracted from patterns like /*date_add::...*/ and /*date_sub::...*/ is inserted into DATE_ADD/DATE_SUB SQL interval expressions without integer casting, and the same flaw exists in the addAppt() function. The fix applied integer casting (int) $days to neutralize the injection (GitHub Advisory, Patch Commit). Affected files include interface/forms/CAMOS/content_parser.php (lines 21, 127, 137, 186) and interface/forms/CAMOS/ajax_save.php (line 28).
Successful exploitation allows an authenticated attacker to execute arbitrary SQL queries against the underlying MariaDB/MySQL database, enabling extraction of sensitive patient health information, user credentials (including bcrypt password hashes from the users_secure table), and other protected health data. Attackers can also modify or delete medical records, potentially compromising data integrity and availability. Given that OpenEMR handles protected health information (PHI), exploitation could result in HIPAA violations and significant regulatory consequences (GitHub Advisory, Feedly).
Public proof-of-concept (PoC) exploit code is available on GitHub, including a Python script (exploit2.py) that performs time-based blind SQL injection to extract data from the users_secure table, and curl-based payloads demonstrating boolean-based blind injection (PoC Repository). The EPSS score is approximately 0.029% (low), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of reporting (Feedly). No threat actor attribution has been identified. Exploitation requires only a valid low-privilege authenticated session, making it accessible to any user with an account on the system.
OpenEMR=<session_id>) and a CSRF token.http://<target>/interface/forms/CAMOS/ajax_save.php via HTTP POST.content parameter using the CAMOS comment syntax, e.g., content=/*date_add::<SQL_PAYLOAD>*/. The $days value extracted from this pattern is concatenated unsanitized into a DATE_ADD SQL interval expression.WHERE 1=1 vs WHERE 1=0) and observe differing server responses to infer data character by character.SLEEP() within the injected interval to confirm injection and enumerate data based on response timing.exploit2.py) to automate extraction of usernames and bcrypt password hashes from the users_secure table: python3 exploit2.py <host> <session_cookie> <csrf_token> users_secure --columns username password./interface/forms/CAMOS/ajax_save.php containing URL-encoded SQL keywords (SLEEP, UNION, SELECT, CHAR, DATE_ADD, WHERE) in the content parameter; repeated requests with slight payload variations indicative of blind injection enumeration.SQL Statement failed on preparation or OpenEMR SQL Escaping ERROR messages originating from content_parser.php or ajax_save.php; web server access logs with POST requests to ajax_save.php containing %2F%2Adate_add%3A%3A (URL-encoded /*date_add::) patterns.SLEEP(), UNION SELECT, or CHAR() functions in the context of form_encounter or users_secure tables.ajax_save.php, consistent with time-based blind SQL injection probing (GitHub Advisory, PoC Repository).The primary remediation is to upgrade OpenEMR to version 8.0.0.3 or later, which applies integer casting (int) $days to the vulnerable SQL interval parameters in content_parser.php and addAppt(), eliminating the injection (Patch Commit, Release Notes). As an interim measure, restrict network access to the CAMOS form endpoint (/interface/forms/CAMOS/ajax_save.php) via firewall or web application firewall (WAF) rules, and limit user privileges to the minimum necessary. Monitor database activity for suspicious SQL injection patterns as described in the IOCs section (GitHub Advisory).
The vulnerability was reported by researcher Christophe SUBLET (ChrisSub08) from Esisar as part of the CyberSkills/Orion project, and credited in the official GitHub Security Advisory (GitHub Advisory). Coverage appeared on The Hacker Wire and was noted on Mastodon and Bluesky shortly after disclosure (Feedly). The vulnerability was also registered with ENISA's European Vulnerability Database (EUVD-2026-16032). No major vendor statements beyond the OpenEMR security advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."