CVE-2026-25164 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: February 25, 2026
OpenEMR - Broken Access Control
Published: February 25, 2026Updated: February 25, 2026Remote Exploitable
Overview
OpenEMR < 8.0.0 contains a broken access control caused by missing authorization checks in REST API document and insurance routes, letting authenticated API clients access or modify all patients' documents and insurance data, exploit requires valid API bearer token.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Authenticated API clients can access or modify all patients' sensitive documents and insurance data, exposing protected health information.
Mitigation
Upgrade to version 8.0.0 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-25164
- Severity
- High
- CVSS Score
- 8.1
- Type
- broken_access_control
- Status
- new
CWE
- CWE-862
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N