CVE-2026-34051: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-34051 is an improper access control vulnerability in OpenEMR's Import/Export functionality that allows low-privileged authenticated users to bypass UI restrictions and perform import/export operations through direct request manipulation. It affects all OpenEMR versions prior to 8.0.0.3 and was disclosed on March 25–26, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is improper authorization (CWE-285) combined with forced browsing (CWE-425): the application enforces access restrictions only at the UI layer (disabling popups for lower-privileged roles such as Receptionist) without implementing server-side ACL checks on the underlying Import/Export endpoints. Specifically, the file custom/export_xml.php lacked an AclMain::aclCheckCore('patients', 'demo') call, meaning any authenticated user could directly navigate to the endpoint URL and perform patient data import or export operations regardless of their assigned role. The fix, committed in patch 81c097f, adds the missing ACL check and an access-denied response for unauthorized users (GitHub Advisory, GitHub Commit).

Impact

Successful exploitation allows any authenticated low-privileged user (e.g., a Receptionist account) to access and manipulate patient health records through the Import/Export functionality, resulting in unauthorized bulk extraction of sensitive patient demographics in XML format and unauthorized injection of fabricated patient records into the system. This poses a significant risk to patient data confidentiality and data integrity within the electronic health records system, and could facilitate HIPAA-relevant data breaches. Availability is not directly impacted (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, providing step-by-step reproduction instructions requiring only a low-privileged authenticated account. The EPSS score is approximately 0.025% (0.000250), indicating low predicted exploitation probability in the near term. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time, and no threat actor attribution has been reported (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Obtain low-privileged credentials: Acquire or use an existing low-privileged OpenEMR account (e.g., a Receptionist role) that would normally have Import/Export UI elements disabled.
  2. Identify the target endpoint: Determine the direct URL for the Import/Export functionality (e.g., custom/export_xml.php or the corresponding import endpoint) on the target OpenEMR instance.
  3. Bypass UI restrictions via forced browsing: Directly navigate to the Import/Export URL in a browser or via an HTTP client (e.g., curl or Burp Suite) while authenticated, bypassing the UI-level popup restrictions that would normally prevent access.
  4. Export patient data: Access the export endpoint to retrieve bulk patient demographic data in XML format, enabling unauthorized data extraction.
  5. Import fabricated data: Craft a malicious XML patient record and submit it via the import endpoint to inject unauthorized patient records into the system (GitHub Advisory).

Indicators of compromise

  • Network: Authenticated HTTP GET/POST requests to custom/export_xml.php or equivalent import endpoints from user accounts with roles that should not have access (e.g., Receptionist); unusual volume of requests to these endpoints.
  • Logs: OpenEMR access logs showing direct navigation to Import/Export URLs by low-privileged user accounts, particularly outside normal business hours or in high frequency; absence of referrer headers indicating direct URL access rather than navigation through the UI.
  • File System: Unexpected XML files containing patient demographic data in directories accessible to web users; newly created patient records with anomalous metadata or creation timestamps inconsistent with normal workflow.
  • Application: Patient records created or modified by user accounts whose roles should not have import/export permissions, visible in OpenEMR audit logs (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenEMR to version 8.0.0.3 or later, which includes the fix adding proper server-side ACL checks to the Import/Export endpoints (GitHub Release, GitHub Commit). As a temporary workaround if immediate patching is not possible, implement network-level access controls (e.g., firewall rules or web server configuration) to restrict access to the custom/export_xml.php and related import endpoints to only trusted IP addresses or administrative users. Review OpenEMR access logs for any suspicious Import/Export activity by low-privileged accounts to assess potential prior exploitation (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher Adi-45 and remediated by OpenEMR developer kojiromike, as credited in the official GitHub Security Advisory. The fix was included as part of the OpenEMR 8.0.0.3 release on March 25, 2026, which addressed a broad set of security issues including multiple high-severity SQL injection, XSS, and authorization bypass vulnerabilities. No significant broader media coverage or notable social media commentary specific to this CVE has been identified (GitHub Advisory, GitHub Release).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management