Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.5

OpenEMR versions before 8.0.0 leak sensitive patient and staff info

CVE-2026-25135
Summary

OpenEMR versions before 8.0.0 can reveal contact information for patients and staff to unauthorized users. This is a concern for organizations that use OpenEMR, especially those with sensitive patient data. To protect your data, update to version 8.0.0 or temporarily restrict access to clients that don't have the vulnerable feature.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
open-emr openemr <= 8.0.0 –
Original title
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 have an information disclosure vulnerability that leaks the entire c...
Original description
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 have an information disclosure vulnerability that leaks the entire contact information for all users, organizations, and patients in the system to anyone who has the system/(Group,Patient,*).$export operation and system/Location.read capabilities. This vulnerability will impact OpenEMR versions since 2023. This disclosure will only occur in extremely high trust environments as it requires using a confidential client with secure key exchange that requires an administrator to enable and grant permission before the app can even be used. This will typically only occur in server-server communication across trusted clients that already have established legal agreements. Version 8.0.0 contains a patch. As a workaround, disable clients that have the vulnerable scopes and only allow clients that do not have the system/Location.read scope until a fix has been deployed.
nvd CVSS3.1 4.5
Vulnerability type
CWE-200 Information Exposure
Published: 25 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026