HIGHCVE-2026-25127Published Modified CNA GitHub_M
CVE-2026-25127: OpenEMR has Broken Access Control on Care Coordination Module
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not properly validate user permission. Unauthorized users can view the information of authorized users. Version 8.0.0 fixes the issue.
Metrics
- CVSS v4.0
- 7.0
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
Affected packages
- openemr / openemr< 8.0.0
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N