A critical security flaw has been found in OpenEMR, a common open-source electronic medical records platform, affecting all versions up to 8.2.0. The issue exists in the part of the software that manages document category trees, and it allows people with administrator access to the OpenEMR site to run harmful, unauthorized commands on the server that hosts the site.
To exploit this flaw, an attacker with administrator access can modify the software's category data to add hidden harmful code. They can also manipulate the software's database to adjust how category ID data is stored, so the harmful code is not blocked. This code runs automatically any time a visitor loads almost any page on the OpenEMR site, even pages that do not require a login or only have limited access. When the code runs, it acts with the same permissions as the web server that hosts your site, letting the attacker take further harmful actions.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-39932