PT-2026-26346 · Openemr · Openemr

·

CVE-2026-33304

·

Published

2026-03-19

·

Updated

2026-03-23

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.2
Description OpenEMR is an electronic health records and medical practice management application. A flaw exists where an authenticated, non-administrator user can view reminder messages belonging to other users. This is achieved by manipulating the sentTo[] or sentBy[] parameters in a GET request to the dated reminders log. The issue allows access to patient names and the content of free-text messages.
Recommendations Update to OpenEMR version 8.0.0.2 or later.

Exploit

Fix

DoS

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05092
CVE-2026-33304
GHSA-66J9-FFQ4-H222

Affected Products

Openemr