CVE-2026-39932 (matched: php)

  • Tuesday, 4th August, 2026
  • 22:04pm

A critical security vulnerability has been identified in OpenEMR, a popular open-source electronic medical records software, affecting all versions released up to 8.2.0. This flaw exists in the software’s document category management feature, and could allow an attacker to run unauthorized, harmful commands on the server that hosts your OpenEMR instance.

To exploit this issue, an attacker would first need to already have administrator-level login access to your OpenEMR installation. They can then modify entries in the software’s category database to insert malicious code, which will automatically run any time the OpenEMR system loads its category lists. This occurs even for public-facing pages or pages accessible to users with very limited access to your OpenEMR system, and the malicious code runs with the same permissions as the web server.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-39932

« Back