LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-34055

CVE-2026-34055 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 26, 2026

OpenEMR - Broken Access Control

Published: March 26, 2026Updated: March 26, 2026Remote Exploitable

Overview

OpenEMR < 8.0.0.3 contains a broken access control caused by lack of authorization checks on patient note updates and deletes in library/pnotes.inc.php, letting authenticated users modify notes they are not authorized to access, exploit requires user authentication.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Authenticated users can modify or delete patient notes they are not authorized to access, risking data integrity and privacy.

Mitigation

Update to version 8.0.0.3 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 26, 2026

🟠 CVE-2026-34055 - High (8.1) OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` with... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-34055/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 26, 2026

🟠 CVE-2026-34055 - High (8.1) OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` with... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-34055/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-34055
Severity
High
CVSS Score
8.1
Type
broken_access_control
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-639

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Score

0.0%Probability of exploitation in the next 30 days