CVE-2026-24849Disclosure(open-emr / openemr)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch open-emr openemr systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. Any authenticated user (regardless of privilege level) can exploit this vulnerability to read sensitive files. Version 7.0.4 patches the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openemr

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-02-25); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
openemr

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-02-25: 4Mentions · 2026-02-26: 1Mentions · 2026-03-02: 1Mentions · 2026-06-08: 1Mentions · 2026-06-09: 1PoC Mentioned / Linked · 2026-06-09: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-06-09: 1Technical Details · 2026-02-25: 4Technical Details · 2026-02-26: 1Technical Details · 2026-03-02: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-09: 102-2502-2603-0206-0806-09
Signal classification3 categories
Disclosure
450.0%
Patch
337.5%
General
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-254
Disclosure2General1Patch1
2026-02-261
Patch1
2026-03-021
Disclosure1
2026-06-081
Disclosure1
2026-06-091
Patch1
Full discourse8 posts
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-24849: OpenEMR < 7.0.4 arbitrary file read via Fax/SMS module allows ANY authenticated user to access sensitive files like DB credentials and system configs. Exploit includes file deletion risk. #DFIR_Radar https://t.co/axPd7YMwdC

    Post summary

    The tweet discloses CVE-2026-24849, an arbitrary file read flaw in OpenEMR’s Fax/SMS module that permits any authenticated user to read sensitive files and potentially delete them, but it does not mention a PoC, exploit tool, or patch.

    12010253
    1.8K followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Patch

    OpenEMR CVE-2026-24849 lets any authenticated user read arbitrary files. Patch to 7.0.4 now. Exploit details and mitigation inside. https://www.redsecuretech.co.uk/blog/post/openemr-cve-2026-24849-arbitrary-file-read-flaw/1229 #OpenEMR #CVE #ArbitraryFileRead #HealthcareCybersecurity #PathTraversal #CWE22 #MedicalDataBreach #PatchNow #OpenEMR7_0_4 https://t.co/VuLyXsIpCD

    Post summary

    The tweet announces CVE-2026-24849, an authenticated arbitrary file read flaw in OpenEMR, highlights that a patch (7.0.4) is available and links to a post with exploit details and mitigation steps.

    0101035
    62 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24849 (CVSS:9.9, CRITICAL) is Analyzed. OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio..https://nvd.nist.gov/vuln/detail/CVE-2026-24849 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-24849 with a high CVSS score but offers no details on exploitation, mitigation, or proof‑of‑concept.

    0000029
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    An arbitrary file read vulnerability (CVE-2026-24849) affects `OpenEMR`, allowing unauthorized access to server files. Update to the fix. #infosec #vulnerability #OpenEMR https://www.pulsepatch.io/posts/cve-2026-24849-openemr-arbitrary-file-read

    Post summary

    The post announces an arbitrary file read vulnerability in OpenEMR (CVE-2026-24849) and urges users to apply the available fix.

    0000038
    1 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24849 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `Et… https://www.cve.org/CVERecord?id=CVE-2026-24849

    Post summary

    The post references CVE‑2026‑24849 in OpenEMR, noting a flaw in the disposeDocument() method before version 7.0.4, but provides no evidence of exploitation, patches, or PoC.

    00000131
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24849 Authenticated File Read Vulnerability in OpenEMR Before 7.0.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24849

    Post summary

    The text announces CVE-2026-24849 as an authenticated file read vulnerability affecting OpenEMR versions before 7.0.4, with no additional details on PoC, exploitation, or patch.

    0000035
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-24849: CRITICAL] Vulnerability in OpenEMR prior to version 7.0.4 allows authenticated users to access sensitive files. Update to version 7.0.4 to patch this issue. #cybersecurity#cve,CVE-2026-24849,#cybersecurity https://cvefind.com/CVE-2026-24849

    Post summary

    The post highlights a critical OpenEMR vulnerability that lets authenticated users read sensitive files and recommends updating to version 7.0.4 to remediate the issue.

    0000046
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-24849** pertains to a critical security flaw in **OpenEMR**, an open-source electronic health records (EHR) and medical practice management application. Prior to version **7.0.4**, the application contains a vulnerability within the `disposeDocument()` method located in the `EtherFaxActions.php` file. This flaw allows **authenticated users**—regardless of their privilege level—to **read arbitrary files** from the server's filesystem. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-24849

    Post summary

    The post announces CVE-2026-24849, a critical file‑read vulnerability in OpenEMR’s EtherFaxActions.php affecting versions prior to 7.0.4, allowing authenticated users to read arbitrary files.

    0000047
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen-emropenemr---

Explore more