LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-33913

CVE-2026-33913 - Vulnerability Analysis

HighCVSS: 7.7

Last Updated: March 26, 2026

OpenEMR - File Inclusion

Published: March 25, 2026Updated: March 26, 2026PoC AvailableRemote Exploitable

Overview

OpenEMR < 8.0.0.3 contains a file inclusion vulnerability caused by improper handling of crafted CCDA documents in the Carecoordination module, letting authenticated users read arbitrary files on the server.

Severity & Score

Severity: High
CVSS Score: 7.7
EPSS Score: 2.7%(Probability of exploitation in next 30 days)

Impact

Authenticated users can read arbitrary files on the server, potentially exposing sensitive information.

Mitigation

Update to version 8.0.0.3 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 25, 2026

🟠 CVE-2026-33913 - High (7.7) OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `` to... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33913/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 25, 2026

🟠 CVE-2026-33913 - High (7.7) OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `` to... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33913/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-33913
Severity
High
CVSS Score
7.7
Type
file_inclusion
Status
confirmed
EPSS
2.7%
Social Posts
2

CWE

  • CWE-611

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS Score

2.7%Probability of exploitation in the next 30 days