CVE-2026-39932 (matched: php)

  • Thursday, 6th August, 2026
  • 16:05pm

A critical security vulnerability, tracked as CVE-2026-39932, has been identified in OpenEMR, an open-source electronic medical records platform, affecting all versions up to 8.2.0. The flaw exists in the software’s document category management feature, and allows someone who already has administrator-level access to the OpenEMR system to run unauthorized commands on the web server that hosts the site.

Attackers can exploit this issue by modifying entries in the software’s categories database table to insert harmful code. This code runs automatically whenever the category management feature loads on any page of the OpenEMR site, even for unauthenticated visitors or users with very limited access to the platform, letting attackers perform actions using the permissions of the web server software.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-39932

« Back