HomeOpen-EmrCVE-2026-25135

CVE-2026-25135

MEDIUM
4.5CVSS
Published: 2026-02-25
Updated: 2026-02-25
AI Analysis

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 have an information disclosure vulnerability that leaks the entire contact information for all users, organizations, and patients in the system to anyone who has the system/(Group,Patient,*).$export operation and system/Location.read capabilities. This vulnerability will impact OpenEMR versions since 2023. This disclosure will only occur in extremely high trust environments as it requires using a confidential client with secure key exchange that requires an administrator to enable and grant permission before the app can even be used. This will typically only occur in server-server communication across trusted clients that already have established legal agreements. Version 8.0.0 contains a patch. As a workaround, disable clients that have the vulnerable scopes and only allow clients that do not have the system/Location.read scope until a fix has been deployed.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Attack Vector
network
Complexity
low
Privileges
high
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
none
Availability
none
Weaknesses
CWE-200

Metadata

Primary Vendor
OPEN-EMR
Published
2/25/2026
Last Modified
2/25/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

open-emr : openemr

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2026-25135 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com