CVE-2026-39932 (matched: php)

  • Monday, 3rd August, 2026
  • 22:03pm

A critical security flaw has been identified in OpenEMR, a common open-source electronic medical records platform, affecting all versions up to 8.2.0. The flaw exists in the software’s document category tree feature, and it allows users with administrative access to the OpenEMR system to sneak harmful executable code into the platform’s category database.

This malicious code is automatically triggered and runs on the web server any time a page that uses the category tree feature loads, even for visitors who are not logged into OpenEMR at all. When the code runs, it executes commands under the same account the website operates with, which could let an attacker steal sensitive data stored in the system, alter website content, or use the compromised server to launch further attacks.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-39932

« Back