CVE-2025-54373
Unauthorized Access in OpenEMR Clinical Notes via Privilege Mismanagement
Publication date: 2026-01-28
Last updated on: 2026-02-12
Assigner: GitHub, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| open-emr | openemr | 7.0.3.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in OpenEMR versions prior to 7.0.4 allows users without the required high sensitivity privileges to view and modify sensitive data in Clinical Notes and Care Plans that are marked with Sensitivity=high. Essentially, unauthorized users can access and change sensitive medical information that should be restricted.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure and modification of sensitive patient health information. This can compromise patient privacy, lead to incorrect medical records, and potentially harm patient care. It also increases the risk of data breaches and loss of trust in the healthcare provider's data security.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability likely causes non-compliance with standards and regulations such as GDPR and HIPAA, which require strict controls over access to sensitive personal and health information. Unauthorized access and modification of sensitive clinical data violate these regulations' requirements for data confidentiality and integrity.
What immediate steps should I take to mitigate this vulnerability?
Upgrade OpenEMR to version 7.0.4 or later, as this version fixes the vulnerability where sensitive data with high sensitivity can be accessed or modified by unauthorized users without the required privileges.