CVE-2026-34056

7.7

OpenEMR · OpenEMR

A broken access control vulnerability in OpenEMR versions up to 8.0.0.3 allows low-privilege users to unauthorizedly access and download sensitive Ensora eRx error logs.

Executive summary

A broken access control vulnerability in OpenEMR allows authenticated low-privilege users to exfiltrate sensitive medical error logs, posing a significant risk to patient data confidentiality.

Vulnerability

This vulnerability involves Improper Authorization (CWE-285) and Forced Browsing (CWE-425) mechanisms, enabling an authenticated low-privilege user to bypass access controls and retrieve sensitive system logs.

Business impact

The compromise of Ensora eRx error logs can lead to the unauthorized disclosure of sensitive medical data, resulting in severe privacy violations and potential regulatory non-compliance. Given the CVSS score of 7.7, this flaw represents a High severity risk that could lead to significant reputational damage and legal liability for healthcare organizations managing patient records.

Remediation

Immediate Action: As no official patch is currently available, administrators should restrict access to the affected directory or disable the eRx error log functionality if not mission-critical.

Proactive Monitoring: Monitor server access logs for anomalous requests directed at eRx log endpoints and investigate any unauthorized attempts by low-privileged user accounts to access administrative or system-level files.

Compensating Controls: Implement Web Application Firewall (WAF) rules to block direct access to log-related endpoints and enforce strict file-level permissions on the server to prevent unauthorized reading of sensitive documents.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a high risk to data privacy due to the exposure of sensitive medical information. Organizations using OpenEMR must prioritize monitoring for unauthorized log access and apply a vendor-supplied patch as soon as it is released to close this security gap.

More OpenEMR CVEs

Sources