CVE-2026-23627
CVSS 8.8 HIGH: openEMR is a free and open source electronic health records and medical practice management application. EPSS 0.8% (54º percentile).
Vulnerabilità · 153 giorni fa
OpenEMR’s main failure mode is access control, not just isolated bugs. When authorization breaks across an EMR platform, a logged-in attacker can reach patient records, alter data, and in some cases turn database access into broader compromise; patching closes the code path, but it does not undo exposure if secrets or records were already taken.
Aisle found 39 flaws in OpenEMR, 38 of them assigned CVEs, through a partnership with OpenEMR developers. The most serious issues were two critical SQL injection bugs, CVE-2026-24908 and CVE-2026-23627, plus CVE-2026-24487, an authorization bypass that could expose patient data; the rest were mostly missing or incorrect authorization, with some XSS, path traversal, and session-expiration issues.
The pattern matters because OpenEMR is used by more than 100,000 healthcare providers and stores data on more than 200 million patients. Repeated authorization failures across modules suggest a systemic design weakness that can put PHI at risk even in deployments that are otherwise firewalled and maintained.
CVSS 8.8 HIGH: openEMR is a free and open source electronic health records and medical practice management application. EPSS 0.8% (54º percentile).
CVSS 9.9 CRITICAL: openEMR is a free and open source electronic health records and medical practice management application. EPSS 0.5% (40º percentile).
CVSS 6.5 MEDIUM: openEMR is a free and open source electronic health records and medical practice management application. EPSS 0.3% (18º percentile).
2 fonti che coprono questa storia
AI Finds 38 Security Flaws in OpenEMR
Flaws in OpenEMR's platform — used by more than 100,000 healthcare providers — enabled database compromise, remote code execution, and data theft.
38 Vulnerabilities Found in OpenEMR Medical Software
Some of the vulnerabilities discovered by Aisle can be exploited to access and alter sensitive patient information.
Part of the PlainSec briefing for 2026-04-30