PT-2026-21816 · Openemr · Openemr

CVE-2025-67752

·

Published

2026-02-25

·

Updated

2026-03-02

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 7.0.4
Description OpenEMR’s HTTP client wrapper (oeHttp/oeHttpRequest) has a default setting that disables SSL/TLS certificate verification (verify: false). This makes all external HTTPS connections susceptible to man-in-the-middle (MITM) attacks. This impacts communication with government healthcare APIs and user-configurable external services, potentially exposing Protected Health Information (PHI).
Recommendations Update to version 7.0.4 or later.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67752
GHSA-2G6H-725P-PQHP

Affected Products

Openemr