216.73.217.174

CVE-2026-25929

· Published 25/02/2026 19:43 · Modified 25/02/2026 19:43

Labels: CVE-2026-25929 2026-02-25CVE-2026-25929CWE-639[email protected]

Essential information

Published
25/02/2026 19:43
Modified
25/02/2026 19:43
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the document controller’s `patient_picture` context serves the patient’s photo by document ID or patient ID without verifying that the current user is authorized to access that patient. An authenticated user with document ACL can supply another patient’s ID and retrieve their photo. Version 8.0.0 fixes the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
openemr / openemr cpe:2.3:a:openemr:openemr:*:*:*:*:*:*:*:*

References