OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including version 8.0.0.3 allows low-privilege users to view and download Ensora eRx error logs without proper authorization checks. This flaw compromises system confidentiality by exposing sensitive information, potentially leading to unauthorized data disclosure and misuse. As of time of publication, no known patches versions are available.
History

Thu, 26 Mar 2026 00:15:00 +0000

Type Values Removed Values Added
Description OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including version 8.0.0.3 allows low-privilege users to view and download Ensora eRx error logs without proper authorization checks. This flaw compromises system confidentiality by exposing sensitive information, potentially leading to unauthorized data disclosure and misuse. As of time of publication, no known patches versions are available.
Title OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data
Weaknesses CWE-285
CWE-425
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-25T23:53:15.789Z

Reserved: 2026-03-25T15:29:04.747Z

Link: CVE-2026-34056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-26T00:16:41.400

Modified: 2026-03-26T00:16:41.400

Link: CVE-2026-34056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.