CVE-2026-24908Disclosure(open-emr / openemr)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Patient REST API endpoint allows authenticated users with API access to execute arbitrary SQL queries through the `_sort` parameter. This could potentially lead to database access, PHI (Protected Health Information) exposure, and credential compromise. The issue occurs when user-supplied sort field names are used in ORDER BY clauses without proper validation or identifier escaping. Version 8.0.0 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openemr

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-25); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openemr

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-25: 1Mentions · 2026-02-26: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 102-2502-26
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-24908 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the… https://www.cve.org/CVERecord?id=CVE-2026-24908

    Post summary

    The text announces an SQL injection vulnerability in OpenEMR before version 8.0.0, but does not provide PoC, exploit, or patch details.

    00000352
    56.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-24908** pertains to an SQL injection vulnerability present in OpenEMR versions prior to 8.0.0. This flaw exists specifically within the Patient REST API endpoint, where an authenticated user with API access can exploit the `_sort` parameter to execute arbitrary SQL queries. The root cause is improper validation and sanitization of user-supplied input used in SQL `ORDER BY` clauses, which allows malicious actors to manipulate database queries. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #SQLInjection #DDoS https://cvetodo.com/cve/CVE-2026-24908

    Post summary

    The post discloses an SQL injection flaw in OpenEMR’s Patient REST API that allows authenticated API users to execute arbitrary SQL queries via the `_sort` parameter.

    0000047
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen-emropenemr---

Explore more