
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34051 is an improper access control vulnerability in OpenEMR's Import/Export functionality that allows low-privileged authenticated users to bypass UI restrictions and perform import/export operations through direct request manipulation. It affects all OpenEMR versions prior to 8.0.0.3 and was disclosed on March 25–26, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Red Hat CVE).
The root cause is improper authorization (CWE-285) combined with forced browsing (CWE-425): the application enforces access restrictions only at the UI layer (disabling popups for lower-privileged roles such as Receptionist) without implementing server-side ACL checks on the underlying Import/Export endpoints. Specifically, the file custom/export_xml.php lacked an AclMain::aclCheckCore('patients', 'demo') call, meaning any authenticated user could directly navigate to the endpoint URL and perform patient data import or export operations regardless of their assigned role. The fix, committed in patch 81c097f, adds the missing ACL check and an access-denied response for unauthorized users (GitHub Advisory, GitHub Commit).
Successful exploitation allows any authenticated low-privileged user (e.g., a Receptionist account) to access and manipulate patient health records through the Import/Export functionality, resulting in unauthorized bulk extraction of sensitive patient demographics in XML format and unauthorized injection of fabricated patient records into the system. This poses a significant risk to patient data confidentiality and data integrity within the electronic health records system, and could facilitate HIPAA-relevant data breaches. Availability is not directly impacted (GitHub Advisory).
A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, providing step-by-step reproduction instructions requiring only a low-privileged authenticated account. The EPSS score is approximately 0.025% (0.000250), indicating low predicted exploitation probability in the near term. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time, and no threat actor attribution has been reported (GitHub Advisory, Red Hat CVE).
custom/export_xml.php or the corresponding import endpoint) on the target OpenEMR instance.curl or Burp Suite) while authenticated, bypassing the UI-level popup restrictions that would normally prevent access.custom/export_xml.php or equivalent import endpoints from user accounts with roles that should not have access (e.g., Receptionist); unusual volume of requests to these endpoints.Upgrade OpenEMR to version 8.0.0.3 or later, which includes the fix adding proper server-side ACL checks to the Import/Export endpoints (GitHub Release, GitHub Commit). As a temporary workaround if immediate patching is not possible, implement network-level access controls (e.g., firewall rules or web server configuration) to restrict access to the custom/export_xml.php and related import endpoints to only trusted IP addresses or administrative users. Review OpenEMR access logs for any suspicious Import/Export activity by low-privileged accounts to assess potential prior exploitation (GitHub Advisory).
The vulnerability was reported by security researcher Adi-45 and remediated by OpenEMR developer kojiromike, as credited in the official GitHub Security Advisory. The fix was included as part of the OpenEMR 8.0.0.3 release on March 25, 2026, which addressed a broad set of security issues including multiple high-severity SQL injection, XSS, and authorization bypass vulnerabilities. No significant broader media coverage or notable social media commentary specific to this CVE has been identified (GitHub Advisory, GitHub Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."