CVE-2026-25164 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: February 27, 2026
OpenEMR - Broken Access Control
Overview
OpenEMR < 8.0.0 contains a broken access control caused by missing authorization checks in REST API document and insurance routes, letting authenticated API clients access or modify all patients' documents and insurance data, exploit requires valid API bearer token.
Severity & Score
Impact
Authenticated API clients can access or modify all patients' sensitive documents and insurance data, exposing protected health information.
Mitigation
Upgrade to version 8.0.0 or later.
References
Social Media Activity(1 post)
š CVE-2026-25164 - High (8.1) OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the REST API route table in `apis/routes/_rest_routes_standard.inc.php` does not call `RestConfig::request_authorizati... š https://www.thehackerwire.com/vulnerability/CVE-2026-25164/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-25164
- Severity
- High
- CVSS Score
- 8.1
- Type
- broken_access_control
- Status
- confirmed
- EPSS
- 8.8%
- Social Posts
- 1
CWE
- CWE-862
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N