PT-2026-78480 · Openemr · Openemr

·

CVE-2026-76614

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.3.0
Description A path traversal issue exists in the EDI archive restore function. The archrestore sel POST parameter is processed by the archive restore handler without proper sanitization for path traversal sequences. This allows an authenticated user with EOB Data Entry permissions to probe arbitrary filesystem paths on the server. The system leaks information about the existence of target files through differing response messages.
Recommendations Update to version 8.3.0 or later. Restrict the use of the archrestore sel parameter in the EDI archive restore function until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76614
GHSA-GFWC-JG5P-JCP4

Affected Products

Openemr