
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33931 is an Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR's patient portal payment page (portal/portal_payment.php) that allows any authenticated portal patient to access other patients' payment records by manipulating the recid query parameter. It affects all OpenEMR versions prior to 8.0.0.3 and was disclosed on March 25, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is CWE-639 (Authorization Bypass Through User-Controlled Key): the portal/portal_payment.php page accepts a user-supplied recid parameter (cast to integer at line 74) and passes it directly to getPortalAuditRec($recid) in portal/lib/appsql.class.php, which queries the onsite_portal_activity table by primary key alone — SELECT * FROM onsite_portal_activity WHERE id = ? — without any patient_id filter. Although the page correctly locks $pid to the session for portal patients, the $recid code path bypasses this entirely. Because onsite_portal_activity.id is an auto-increment integer, valid record IDs are trivially enumerable. The fix, applied in commit 7bf30e0, adds an optional $patientId parameter to getPortalAuditRec() and passes the session $pid when the caller is a portal patient, enforcing WHERE id = ? AND patient_id = ? (GitHub Advisory, Patch Commit).
Successful exploitation exposes Protected Health Information (PHI) and partial payment card data across all patients who have used the portal payment feature. The disclosed data includes invoice/billing PHI (patient name, amounts, services, diagnoses) for all payment gateway types, and for InHouse-gateway installations additionally exposes cardholder name, last four card digits, expiration date, CVV, and zip code. There is no integrity or availability impact, but the confidentiality breach affects all patients enrolled in the portal, creating significant HIPAA compliance risk and potential PCI DSS exposure for affected healthcare organizations (GitHub Advisory).
A proof-of-concept is publicly documented in the official GitHub Security Advisory, providing step-by-step instructions for exploiting the vulnerability by navigating to /portal/portal_payment.php?recid=<id> as any authenticated portal patient. The EPSS score is approximately 0.027%, and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of disclosure. No threat actor attribution has been reported (GitHub Advisory, Feedly).
/portal/portal_payment.php without a recid parameter to confirm the portal payment page loads patient A's own data./portal/portal_payment.php?recid=1, ?recid=2, etc. Since onsite_portal_activity.id is an auto-increment integer, valid IDs belonging to other patients can be discovered by iterating through small integers.recid belonging to another patient (patient B), the response renders patient B's invoice/billing PHI in the jsondata JavaScript variable and payment card metadata (cardholder name, masked card number, expiration, CVV for InHouse gateway, zip) in the payment-information panel./portal/portal_payment.php with sequentially incrementing recid query parameter values from a single authenticated session or IP address.portal_payment.php?recid=<N> across a range of integer values in a short time window; responses returning HTTP 200 for records not belonging to the authenticated patient.getPortalAuditRec() calls with recid values that do not correspond to the authenticated patient's own records.Upgrade OpenEMR to version 8.0.0.3 or later, which patches the vulnerability by adding a patient_id filter to getPortalAuditRec() when called from a portal patient session (OpenEMR Release, Patch Commit). For organizations unable to patch immediately, consider disabling the patient portal payment feature or implementing a web application firewall rule to block requests to portal/portal_payment.php containing a recid parameter from non-staff sessions. Additionally, monitor web server logs for sequential recid enumeration patterns as a detective control (GitHub Advisory).
The vulnerability was reported by researchers pavelkohout396 and simecek, with remediation development credited to kojiromike, and was published as a GitHub Security Advisory by OpenEMR maintainer adunsulag on March 25, 2026. It was one of 18 security fixes bundled in the OpenEMR 8.0.0.3 release, which also addressed multiple SQL injection, XSS, and missing authorization issues. Coverage appeared on security aggregation sites including exploit-intel.com and infinitsec.net shortly after disclosure (GitHub Advisory, OpenEMR Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."