CVE-2026-34056
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2026-34056 is a Broken Access Control (Privilege Escalation) vulnerability in OpenEMR, a widely used open-source electronic health records and medical practice management application. It allows low-privilege authenticated users to view and download Ensora eRx (electronic prescribing) error logs without proper authorization checks, exposing sensitive healthcare data. The vulnerability affects OpenEMR version 7.0.4 and was disclosed on March 25–26, 2026. A patch was released in version 8.0.0.3. It carries a CVSS v3.1 base score of 7.7 (High) per the GitHub Security Advisory, or 6.5 (Medium) per NVD scoring (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is improper authorization (CWE-285) combined with Direct Request / Forced Browsing (CWE-425): the endpoint interface/logview/erx_logview.php does not enforce role-based access control (RBAC) checks before serving Ensora eRx error log data. A low-privilege user (e.g., a Physician-level account) who lacks access to administrative modules can directly navigate to the unprotected URL and retrieve or download the logs without any server-side authorization validation. The advisory confirms the affected endpoint is accessible at https://demo.openemr.io/openemr/interface/logview/erx_logview.php, and a step-by-step proof-of-concept demonstrating the forced browsing technique is included in the GitHub Security Advisory (GitHub Advisory).

Impact

Successful exploitation allows any authenticated low-privilege user to access and download Ensora eRx error logs that are intended to be restricted to administrators, violating role-based access controls and system confidentiality. These logs may contain sensitive healthcare information such as prescription data, patient identifiers, or system configuration details, creating risk of unauthorized data disclosure and potential HIPAA compliance violations. There is no integrity or availability impact; the vulnerability is purely a confidentiality breach (GitHub Advisory, Red Hat CVE).

Exploitability

A proof-of-concept (PoC) demonstrating the forced browsing technique is publicly available in the GitHub Security Advisory, with high confidence that it is reproducible. The EPSS score is approximately 0.028% (0.000280), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of publication. Exploitation requires only a valid low-privilege account on the target OpenEMR instance, making it accessible to any authenticated user (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify an internet-facing or network-accessible OpenEMR instance running version 7.0.4 or earlier up to 8.0.0.3 using tools like Shodan or Censys, or through direct knowledge of the target environment.
  2. Obtain low-privilege credentials: Authenticate to the OpenEMR application using any valid low-privilege account (e.g., a Physician-level user) that does not have access to administrative modules.
  3. Direct request to unprotected endpoint: While authenticated, navigate directly to the vulnerable URL: https://<target>/openemr/interface/logview/erx_logview.php — bypassing the UI-level access restrictions that hide this page from non-admin users.
  4. Access and download eRx error logs: The server returns the Ensora eRx error log content without performing any server-side authorization check, allowing the attacker to view and download sensitive log data that should be restricted to administrators (GitHub Advisory).

Indicators of compromise

  • Network: HTTP GET requests from non-administrative user sessions to /openemr/interface/logview/erx_logview.php; repeated access to this endpoint from accounts not associated with administrative roles.
  • Logs: Web server access logs (Apache/Nginx) showing successful HTTP 200 responses to erx_logview.php from low-privilege user sessions; OpenEMR application logs showing access to the eRx log viewer by non-admin accounts.
  • Behavioral: User accounts with Physician or other low-privilege roles accessing administrative log endpoints outside of normal workflow patterns; unusual download activity of log files from non-admin sessions (GitHub Advisory).

Mitigation and workarounds

OpenEMR released version 8.0.0.3 on March 25, 2026, which includes a fix described as "Missing ACL check on eRx log viewer" among numerous other security fixes. Administrators should upgrade to OpenEMR 8.0.0.3 or later immediately. As a temporary workaround, restrict network access to the OpenEMR instance to trusted networks only, and consider blocking direct access to /interface/logview/erx_logview.php at the web server or firewall level for non-administrative users. Monitor access logs for unauthorized attempts to access the sensitive log endpoint (GitHub Advisory, OpenEMR Release).

Community reactions

The vulnerability was reported by security researcher Adi-45 and published via the GitHub Security Advisory program on March 25, 2026. Social media activity was observed on Mastodon and Bluesky shortly after disclosure, with community posts highlighting the privilege escalation risk in a healthcare application context. The infinitsec.net blog published a write-up framing the issue as a privilege escalation allowing low-level users to view admin-only data (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-39932CRITICAL9.4
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoNoAug 03, 2026
CVE-2026-67611HIGH8.6
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoNoAug 03, 2026
CVE-2026-67610HIGH8.6
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoNoAug 03, 2026
CVE-2026-39931HIGH8.6
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoNoAug 03, 2026
CVE-2026-67612MEDIUM4.8
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoNoAug 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management