PT-2026-67439 · Openemr · Openemr

·

CVE-2026-67610

·

Published

2026-04-12

·

Updated

2026-08-03

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.2.0
Description An improper authentication issue exists in the OAuth2 dynamic client registration endpoint. Unauthenticated attackers can register a malicious client with system-level FHIR (Fast Healthcare Interoperability Resources, a standard for exchanging electronic health records) scopes by providing a self-generated RSA keypair through the jwks field. After an administrator approves the client, the attacker can use the client credentials grant with a self-signed JWT (JSON Web Token) assertion to obtain access tokens, granting read access to all FHIR resources for all patients in the system.
Recommendations Update OpenEMR to version 8.2.0 or later. Restrict access to the OAuth2 dynamic client registration endpoint to prevent unauthorized client registrations.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11005
CVE-2026-67610

Affected Products

Openemr