HIGH🇵🇱 Wersja polska

CVE-2026-67611

CVSS 8.6v4.0pub. 2026-08-03upd. 2026-09-01

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Open Emr Openemr

    APP
    Open-Emr
    ≤ 8.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-39932CRITICAL9.4PL ✓same product

RCE w OpenEMR przez eval() injection w komponencie CategoryTree

CVE-2026-32238CRITICAL9.1PL ✓same product

Command Injection w funkcji backup OpenEMR (wersje przed 8.0.0.2)

CVE-2026-24898CRITICAL10.0PL ✓same product

OpenEMR: ujawnienie tokenów API MedEx bez uwierzytelnienia (Auth Bypass)

CVE-2026-25146CRITICAL9.6PL ✓same product

OpenEMR: Wyciek klucza API bramki płatności do klienta w plaintext

CVE-2026-24908CRITICAL9.9PL ✓same product

SQL Injection w OpenEMR — narażenie danych PHI przez parametr _sort