logo

Critical RCE Vulnerability in OpenEMR Exposes Servers to Attacks

ID: e8f7985b-abe7-5bd6-b57d-e1bff1bd23b2

STIX ID: report--e8f7985b-abe7-5bd6-b57d-e1bff1bd23b2

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

...
...

A critical RCE vulnerability (CVE-2026-39932) in OpenEMR ≤ 8.2.0 stems from an unsafe eval() in the document category tree, permitting attackers to inject and execute PHP from the categories database (administrators can alter the id column to VARCHAR to insert payloads). Exploitation can lead to command execution as the web server user and may be triggered via authenticated or unauthenticated page activities; CVSS scores are 9.4 (CVSS 4.0) and 9.1 (CVSS 3.1). Immediate upgrade to OpenEMR 8.2.1+ and review of database integrity and access controls is recommended; vulnerability was publicly reported on 2026-08-03.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.