CVE-2026-32123

HIGH

OpenEMR < 8.0.0.1 - Incorrect Authorization for Group Encounters

Title source: llm
STIX 2.1

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for group encounters are broken because the code only consults form_encounter for sensitivity, while group encounters store sensitivity in form_groups_encounter. As a result, sensitivity is never correctly applied to group encounters, and users who should be restricted from viewing sensitive (e.g. mental health) encounters can view them. This vulnerability is fixed in 8.0.0.1.

References (1)

Core 1
Core References

Scores

CVSS v3 7.7
EPSS 0.0025
EPSS Percentile 16.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
open-emr/openemr < 8.0.0.1
Published Mar 11, 2026
Tracked Since Mar 12, 2026