PT-2026-76784 · Openemr · Openemr

·

CVE-2026-40506

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.2.0
Description A path traversal issue exists in the 'standard tables manage.php' interface. The db GET parameter is passed without validation to the temp dir cleanup() function, which appends the value to the PHP temporary directory path and recursively deletes the resulting directory. By using a traversal sequence in the db parameter and combining it with an open redirect in 'dicom frame.php', an unauthenticated attacker can send a crafted URL that causes arbitrary recursive directory deletion when accessed by an authenticated Superuser session.
Recommendations Update to version 8.2.0 or later. As a temporary mitigation, restrict access to the 'standard tables manage.php' interface or avoid using the db parameter until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40506
GHSA-HJ9X-33VW-5G3X

Affected Products

Openemr