OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and export actions through direct request manipulation despite UI restrictions. This can lead to unauthorized data access, bulk data extraction, and manipulation of system data. Version 8.0.0.3 contains a fix.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and export actions through direct request manipulation despite UI restrictions. This can lead to unauthorized data access, bulk data extraction, and manipulation of system data. Version 8.0.0.3 contains a fix. | |
| Title | OpenEMR has Improper ACL On Import/Export Popup | |
| Weaknesses | CWE-285 CWE-425 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-25T23:45:06.656Z
Updated: 2026-03-25T23:45:06.656Z
Reserved: 2026-03-25T15:29:04.746Z
Link: CVE-2026-34051
No data.
Status : Received
Published: 2026-03-26T00:16:40.850
Modified: 2026-03-26T00:16:40.850
Link: CVE-2026-34051
No data.