CVE-2026-24898Disclosure(open-emr / openemr)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch open-emr openemr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the practice's MedEx API tokens, leading to complete third-party service compromise, PHI exfiltration, unauthorized actions on the MedEx platform, and HIPAA violations. The vulnerability exists because the endpoint bypasses authentication ($ignoreAuth = true) and performs a MedEx login whenever $_POST['callback_key'] is provided, returning the full JSON response including sensitive API tokens. This vulnerability is fixed in 8.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openemr

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-03-03); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
openemr

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-03: 3Mentions · 2026-03-04: 2Mentions · 2026-03-06: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-03: 3Technical Details · 2026-03-04: 2Technical Details · 2026-03-06: 103-0303-0403-06
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-033
Disclosure1General1Patch1
2026-03-042
Disclosure2
2026-03-061
Patch1
Full discourse6 posts
  • maru@maru1151157
    Patch

    🚨 CVE-2026-24898 (CVSS: 10.0) OpenEMR 8.0.0以前では、MedExコールバックエンドポイントで未認証ユーザーがAPIトークンを取得可能。これにより、THIRD-PARTYサービス侵害、PHI漏洩、HIPAA違反のリスク。8.0.0に更新で修正。 https://maruomosquit.com/vulnerability/CVE-2026-24898/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-24898 allows unauthenticated users to obtain API tokens via the MedEx callback endpoint in OpenEMR versions prior to 8.0.0, risking PHI exposure; upgrading to 8.0.0 resolves the issue.

    00080278
    1.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24898 Unauthenticated MedEx API Token Disclosure in OpenEMR Versions Prior to 8.0.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24898

    Post summary

    The text announces CVE-2026-24898, describing an unauthenticated API token disclosure in OpenEMR versions before 8.0.0, with no additional details on exploitation or mitigation.

    0001043
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-24898 - Critical OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx cal... https://www.thehackerwire.com/vulnerability/CVE-2026-24898/ https://t.co/SLoJ6azJbG

    Post summary

    The tweet announces a critical unauthenticated token disclosure vulnerability in OpenEMR versions prior to 8.0.0, linking to a detailed article for more information.

    0000031
    121 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-24898 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerabi… https://www.cve.org/CVERecord?id=CVE-2026-24898 ----- Traducción: CVE-2026-24898 Ope… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-24898, noting an unauthenticated token disclosure vulnerability in OpenEMR versions before 8.0.0, but offers no further technical details, PoC, or mitigation information.

    0000035
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24898 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerabi… https://www.cve.org/CVERecord?id=CVE-2026-24898

    Post summary

    The text announces CVE-2026-24898, an unauthenticated token disclosure vulnerability affecting OpenEMR versions before 8.0.0, without providing details on exploitation, mitigation, or PoC.

    00000603
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-24898: CRITICAL] Vulnerability in OpenEMR < 8.0.0 allows unauthorized access to MedEx API tokens, risking PHI exposure and third-party service compromise. Update to version 8.0.0 for a fix.#cve,CVE-2026-24898,#cybersecurity https://cvefind.com/CVE-2026-24898

    Post summary

    The post highlights a critical CVE in OpenEMR that allows unauthorized access to MedEx API tokens and advises users to update to version 8.0.0 to mitigate the risk.

    0000048
    593 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen-emropenemr---

Explore more