CVE-2026-39932 (matched: php)

  • Wednesday, 5th August, 2026
  • 16:05pm

A critical security flaw has been discovered in OpenEMR, a widely used open-source electronic medical records platform, affecting all versions up to 8.2.0. The vulnerability exists in the part of the software that manages organized document category trees for medical records and related files.

The flaw allows someone with existing administrator-level access to the OpenEMR dashboard to run any command on the server hosting the platform. They can inject malicious code into the software's category database settings, which is then automatically executed whenever any page on the site loads the category tree feature — even for unauthenticated visitors or users with very limited access to the platform. This gives an attacker the ability to fully control the server, steal sensitive data, or disrupt your website and related services.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-39932

« Back