CVE-2026-33931: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-33931 is an Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR's patient portal payment page (portal/portal_payment.php) that allows any authenticated portal patient to access other patients' payment records by manipulating the recid query parameter. It affects all OpenEMR versions prior to 8.0.0.3 and was disclosed on March 25, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is CWE-639 (Authorization Bypass Through User-Controlled Key): the portal/portal_payment.php page accepts a user-supplied recid parameter (cast to integer at line 74) and passes it directly to getPortalAuditRec($recid) in portal/lib/appsql.class.php, which queries the onsite_portal_activity table by primary key alone — SELECT * FROM onsite_portal_activity WHERE id = ? — without any patient_id filter. Although the page correctly locks $pid to the session for portal patients, the $recid code path bypasses this entirely. Because onsite_portal_activity.id is an auto-increment integer, valid record IDs are trivially enumerable. The fix, applied in commit 7bf30e0, adds an optional $patientId parameter to getPortalAuditRec() and passes the session $pid when the caller is a portal patient, enforcing WHERE id = ? AND patient_id = ? (GitHub Advisory, Patch Commit).

Impact

Successful exploitation exposes Protected Health Information (PHI) and partial payment card data across all patients who have used the portal payment feature. The disclosed data includes invoice/billing PHI (patient name, amounts, services, diagnoses) for all payment gateway types, and for InHouse-gateway installations additionally exposes cardholder name, last four card digits, expiration date, CVV, and zip code. There is no integrity or availability impact, but the confidentiality breach affects all patients enrolled in the portal, creating significant HIPAA compliance risk and potential PCI DSS exposure for affected healthcare organizations (GitHub Advisory).

Exploitability

A proof-of-concept is publicly documented in the official GitHub Security Advisory, providing step-by-step instructions for exploiting the vulnerability by navigating to /portal/portal_payment.php?recid=<id> as any authenticated portal patient. The EPSS score is approximately 0.027%, and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of disclosure. No threat actor attribution has been reported (GitHub Advisory, Feedly).

Exploitation steps

  1. Obtain portal credentials: Register or obtain valid credentials for any patient account on the target OpenEMR patient portal (no staff/admin privileges required).
  2. Authenticate: Log into the patient portal as patient A using a standard browser or HTTP client.
  3. Identify the vulnerable endpoint: Navigate to /portal/portal_payment.php without a recid parameter to confirm the portal payment page loads patient A's own data.
  4. Enumerate record IDs: Sequentially request /portal/portal_payment.php?recid=1, ?recid=2, etc. Since onsite_portal_activity.id is an auto-increment integer, valid IDs belonging to other patients can be discovered by iterating through small integers.
  5. Extract cross-patient data: For each valid recid belonging to another patient (patient B), the response renders patient B's invoice/billing PHI in the jsondata JavaScript variable and payment card metadata (cardholder name, masked card number, expiration, CVV for InHouse gateway, zip) in the payment-information panel.
  6. Exfiltrate data: Collect and store the returned PHI and payment card metadata for all enumerated records (GitHub Advisory).

Indicators of compromise

  • Network: Repeated HTTP GET requests to /portal/portal_payment.php with sequentially incrementing recid query parameter values from a single authenticated session or IP address.
  • Logs: Web server access logs showing a single portal user session making many requests to portal_payment.php?recid=<N> across a range of integer values in a short time window; responses returning HTTP 200 for records not belonging to the authenticated patient.
  • Application Logs: OpenEMR audit logs showing getPortalAuditRec() calls with recid values that do not correspond to the authenticated patient's own records.
  • Behavioral: A portal patient account accessing payment records at an unusually high rate or outside normal business hours (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0.3 or later, which patches the vulnerability by adding a patient_id filter to getPortalAuditRec() when called from a portal patient session (OpenEMR Release, Patch Commit). For organizations unable to patch immediately, consider disabling the patient portal payment feature or implementing a web application firewall rule to block requests to portal/portal_payment.php containing a recid parameter from non-staff sessions. Additionally, monitor web server logs for sequential recid enumeration patterns as a detective control (GitHub Advisory).

Community reactions

The vulnerability was reported by researchers pavelkohout396 and simecek, with remediation development credited to kojiromike, and was published as a GitHub Security Advisory by OpenEMR maintainer adunsulag on March 25, 2026. It was one of 18 security fixes bundled in the OpenEMR 8.0.0.3 release, which also addressed multiple SQL injection, XSS, and missing authorization issues. Coverage appeared on security aggregation sites including exploit-intel.com and infinitsec.net shortly after disclosure (GitHub Advisory, OpenEMR Release).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management