LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-25745

CVE-2026-25745 - Vulnerability Analysis

MediumCVSS: 6.5

Last Updated: March 19, 2026

OpenEMR - Broken Access Control

Published: March 18, 2026Updated: March 19, 2026PoC AvailableRemote Exploitable

Overview

OpenEMR <= 8.0.0 contains a broken access control caused by lack of verification on message/note ownership in the update endpoint, letting authenticated users with notes permission modify any patient's messages, exploit requires user authentication with notes permission.

Severity & Score

Severity: Medium
CVSS Score: 6.5

Impact

Authenticated users with notes permission can modify any patient's messages, risking data integrity and patient confidentiality.

Mitigation

Update to a version including commit 92a2ff9eaaa80674b3a934a6556e35e7aded5a41 or later.

Details

CVE ID
CVE-2026-25745
Severity
Medium
CVSS Score
6.5
Type
broken_access_control
Status
confirmed

CWE

  • CWE-639

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N