A critical security vulnerability, tracked as CVE-2026-39932, has been found in OpenEMR, a popular open-source medical practice and patient records software, that affects all versions up to and including 8.2.0. This flaw applies to any customer running an OpenEMR instance on their hosted web hosting account.
The vulnerability exists in the part of the software that manages document categories. To exploit it, an attacker first needs to gain access to an OpenEMR administrator account. Once they have that access, they can inject harmful code into the software's database. This malicious code will automatically run any time a page on the OpenEMR site loads, even for pages that regular visitors or unauthenticated users can access.
When the harmful code runs, it lets the attacker execute any commands on the server hosting your OpenEMR site, with the same permissions as the web server software. This could allow them to view, modify, or delete your site's data, or even use your server to attack other websites or systems.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-39932