LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-32238

open-emr · openemr

Published
CVSS9.1
Severitycritical
WeaknessCWE-78
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the backup functionality. Version 8.0.0.2 fixes the issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32238

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32238.