DFIR Radar[verified]@DFIR_RadarDisclosure
The tweet discloses CVE-2026-24849, an arbitrary file read flaw in OpenEMR’s Fax/SMS module that permits any authenticated user to read sensitive files and potentially delete them, but it does not mention a PoC, exploit tool, or patch.
CVETodo[verified]@CveTodoDisclosure
The post announces CVE-2026-24849, a critical file‑read vulnerability in OpenEMR’s EtherFaxActions.php affecting versions prior to 7.0.4, allowing authenticated users to read arbitrary files.
Red Secure Tech Ltd.@redsecuretechPatch
The tweet announces CVE-2026-24849, an authenticated arbitrary file read flaw in OpenEMR, highlights that a patch (7.0.4) is available and links to a post with exploit details and mitigation steps.
CRAC Learning - Tech@cracbotDisclosure
The post references CVE-2026-24849 with a high CVSS score but offers no details on exploitation, mitigation, or proof‑of‑concept.
PulsePatch.io@pulsepatchioPatch
The post announces an arbitrary file read vulnerability in OpenEMR (CVE-2026-24849) and urges users to apply the available fix.
CVE@CVEnewGeneral
The post references CVE‑2026‑24849 in OpenEMR, noting a flaw in the disposeDocument() method before version 7.0.4, but provides no evidence of exploitation, patches, or PoC.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces CVE-2026-24849 as an authenticated file read vulnerability affecting OpenEMR versions before 7.0.4, with no additional details on PoC, exploitation, or patch.
CVEFind.com@CveFindComPatch
The post highlights a critical OpenEMR vulnerability that lets authenticated users read sensitive files and recommends updating to version 7.0.4 to remediate the issue.