CVE-2025-67645Disclosure(open-emr / openemr)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch open-emr openemr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the Profile Edit endpoint. An authenticated normal user can modify the request parameters (pubpid / pid) to reference another user’s record; the server accepts the modified IDs and applies the changes to that other user’s profile. This allows one user to alter another user’s profile data (name, contact info, etc.), and could enable account takeover. Version 7.0.4 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openemr

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-01-28); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openemr

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-01-27: 1Mentions · 2026-01-28: 2Mentions · 2026-02-02: 1Patch / Workaround · 2026-01-28: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 2Technical Details · 2026-02-02: 101-2701-2802-02
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-271
Disclosure1
2026-01-282
Disclosure1Patch1
2026-02-021
Disclosure1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-67645 (CVSS:8.8, HIGH) is Undergoing Analysis. OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ..https://nvd.nist.gov/vuln/detail/CVE-2025-67645 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE‑2025‑67645, a high‑severity vulnerability in OpenEMR, is under analysis and referenced via the NVD link, but no PoC, exploit, or patch details are provided.

    0000038
    171 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    OpenEMR has a Broken Access Control vulnerability (CVE-2025-67645) in its Profile Edit Endpoint. Update to version 466c4a32aa633b98a382c35f45fd902688ed83e7 or later to mitigate. #OpenEMR #InfoSec https://www.pulsepatch.io/posts/cve-2025-67645-openemr-broken-access-control

    Post summary

    OpenEMR’s CVE-2025-67645 is a broken access control flaw affecting the Profile Edit Endpoint; users should update to the patched version to mitigate the risk.

    0000069
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-67645 Authenticated Broken Access Control in OpenEMR Profile Edit Endpoint Before 7.0.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-67645

    Post summary

    The post announces CVE-2025-67645, detailing an authenticated broken access‑control vulnerability in the OpenEMR profile edit endpoint before v7.0.4, but offers no PoC, exploit, or patch information.

    0000070
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-67645 OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the P… https://www.cve.org/CVERecord?id=CVE-2025-67645

    Post summary

    CVE‑2025‑67645 is a broken access control vulnerability affecting OpenEMR versions before 7.0.4, as announced on CVE.org, with no exploit, PoC, or patch details disclosed in the excerpt.

    00000286
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen-emropenemr7.0.3--

Explore more