


Perceptive Security
SOC/SIEM Consultancy

OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two pa…
Published:
2 March 2026 at 23:00:00
Alert date:
3 March 2026 at 23:01:36
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
OpenEMR versions 5.0.2 through 7.x.x contain a critical vulnerability where gateway_api_key secret values are rendered to clients in plaintext through at least two code paths. This information disclosure affects the payment processing functionality and could lead to arbitrary money movement or complete account takeover of payment gateway APIs. The vulnerability impacts the front_payment.php and portal_payment.php files. Organizations using OpenEMR for medical practice management should prioritize upgrading to version 8.0.0 where this issue has been resolved.
Technical details
Mitigation steps:
Affected products:
OpenEMR
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-25146
https://github.com/openemr/openemr/blob/6a4e18c5ec73e0c755f6f65b28a9652aded1a58b/interface/patient_file/front_payment.php#L765
https://github.com/openemr/openemr/blob/6a4e18c5ec73e0c755f6f65b28a9652aded1a58b/portal/portal_payment.php#L537
https://github.com/openemr/openemr/commit/fe6341496dc82d5b4f5a3f35891bb2e2481f3b25
https://github.com/openemr/openemr/security/advisories/GHSA-2hq8-wc73-jvvq
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
