Disclosure
**CVE-2026-24890** pertains to an authorization bypass in the OpenEMR patient portal, specifically within the signature management endpoint. Prior to version 8.0.0, authenticated users with access to the patient portal could exploit a flaw by setting the `type=admin-signature` parameter and specifying any provider user ID, thereby overwriting provider signatures without proper authorization checks. This flaw allows users to forge provider signatures on medical documents, potentially leading to legal and compliance issues.
#Cybersecurity #CVE #HighSeverity #SecurityAlert #AuthBypass https://cvetodo.com/cve/CVE-2026-24890
Post summary
The post discloses an authorization bypass in OpenEMR that permits forging provider signatures, providing technical details but no PoC, exploit, or patch information.