


Perceptive Security
SOC/SIEM Consultancy

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in…
Published:
27 January 2026 at 23:00:00
Alert date:
28 January 2026 at 01:03:02
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access
OpenEMR, a free and open source electronic health records application, contains a broken access control vulnerability in versions prior to 7.0.4. The vulnerability exists in the Profile Edit endpoint where authenticated users can modify request parameters (pubpid/pid) to reference and alter other users' records. This allows unauthorized modification of profile data including names and contact information, potentially enabling account takeover attacks. The issue has been resolved in version 7.0.4 with appropriate access controls implemented.
Technical details
Mitigation steps:
Affected products:
OpenEMR
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-67645
https://github.com/openemr/openemr/commit/e2a682ee71aac71a9f04ae566f4ffca10052bc4a
https://github.com/openemr/openemr/security/advisories/GHSA-vjmv-cf46-gffv
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
