CVE-2025-54373
Unknown Unknown - Not Provided
Unauthorized Access in OpenEMR Clinical Notes via Privilege Mismanagement

Publication date: 2026-01-28

Last updated on: 2026-02-12

Assigner: GitHub, Inc.

Description
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes and Care Plan, where an encounter has Sensitivity=high, can be viewed and changed by users who do not have Sensitivities=high privilege. Version 7.0.4 fixes the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-28
Last Modified
2026-02-12
Generated
2026-05-07
AI Q&A
2026-01-29
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
open-emr openemr 7.0.3.4
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in OpenEMR versions prior to 7.0.4 allows users without the required high sensitivity privileges to view and modify sensitive data in Clinical Notes and Care Plans that are marked with Sensitivity=high. Essentially, unauthorized users can access and change sensitive medical information that should be restricted.


How can this vulnerability impact me? :

The vulnerability can lead to unauthorized disclosure and modification of sensitive patient health information. This can compromise patient privacy, lead to incorrect medical records, and potentially harm patient care. It also increases the risk of data breaches and loss of trust in the healthcare provider's data security.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

This vulnerability likely causes non-compliance with standards and regulations such as GDPR and HIPAA, which require strict controls over access to sensitive personal and health information. Unauthorized access and modification of sensitive clinical data violate these regulations' requirements for data confidentiality and integrity.


What immediate steps should I take to mitigate this vulnerability?

Upgrade OpenEMR to version 7.0.4 or later, as this version fixes the vulnerability where sensitive data with high sensitivity can be accessed or modified by unauthorized users without the required privileges.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart