CRITICAL🇵🇱 Wersja polska

CVE-2026-32238

CVSS 9.1v3.1pub. 2026-03-19upd. 2026-03-20

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the backup functionality. Version 8.0.0.2 fixes the issue.

🤖 AI Analysis
How it works

The vulnerability results from insufficient input validation in the backup functionality. An authenticated attacker can provide crafted data containing malicious system commands that will be executed by the application in the server context. Lack of proper filtering or escaping of input data (CWE-78) enables injection and execution of arbitrary system commands on the server side.

Impact

An attacker can gain full control over the server system, including access to confidential patient medical data, ability to modify or delete data, as well as remote code execution (RCE) with application privileges. High impact on system confidentiality, integrity and availability is confirmed by the CVSS vector.

Mitigation & patch

OpenEMR should be updated immediately to version 8.0.0.2, which contains a patch eliminating the vulnerability. Detailed information is available in the manufacturer's GitHub repository (commit 7bc7bd077a624e205daed17658de41af6070ef73) and in the official security advisory GHSA-6pmc-3xm7-pm86.

Who is affected

OpenEMR in all versions preceding 8.0.0.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Open Emr Openemr

    APP
    Open-Emr
    < 8.0.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-25146CRITICAL9.6PL ✓same product

OpenEMR: Wyciek klucza API bramki płatności do klienta w plaintext

CVE-2026-24898CRITICAL10.0PL ✓same product

OpenEMR: ujawnienie tokenów API MedEx bez uwierzytelnienia (Auth Bypass)

CVE-2026-24908CRITICAL9.9PL ✓same product

SQL Injection w OpenEMR — narażenie danych PHI przez parametr _sort

CVE-2026-24849CRITICAL9.9PL ✓same product

OpenEMR: path traversal umożliwia odczyt dowolnych plików przez uwierzytelnionego użytkownika

CVE-2024-22611CRITICAL9.8PL ✓same product

SQL Injection w OpenEMR 7.0.2 — krytyczna podatność w module aptecznym