Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
OpenEMR: Malicious Code Can Access Patient Data
CVE-2026-25746
Summary
OpenEMR, a free application for managing medical records, has a security flaw that allows attackers to access sensitive information about patients. This issue affects versions of the software released before 8.0.0. Update to version 8.0.0 or later to protect patient data.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| open-emr | openemr | <= 8.0.0 | – |
Original title
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulnerability in prescription that can be ex...
Original description
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulnerability in prescription that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the prescription listing functionality. Version 8.0.0 fixes the vulnerability.
nvd CVSS3.1
8.8
Vulnerability type
CWE-89
SQL Injection
- https://github.com/ChrisSub08/CVE-2026-25746_SqlInjectionVulnerabilityOpenEMR7.0... Exploit Third Party Advisory
- https://github.com/openemr/openemr/blob/2b46e594b9dd665fb7f16c913ca07f5c6d54412b... Product
- https://github.com/openemr/openemr/blob/9fa8db9f12d0b70985195b11b90f2dc564bd3b24... Product
- https://github.com/openemr/openemr/blob/9fa8db9f12d0b70985195b11b90f2dc564bd3b24... Product
- https://github.com/openemr/openemr/blob/9fa8db9f12d0b70985195b11b90f2dc564bd3b24... Product
- https://github.com/openemr/openemr/commit/e230d3ef46425ffc96a37dc6369428aa37c885... Patch
- https://github.com/openemr/openemr/security/advisories/GHSA-78r7-g65p-gpw3 Exploit Vendor Advisory
Published: 25 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026