Disclosure
**CVE-2026-24908** pertains to an SQL injection vulnerability present in OpenEMR versions prior to 8.0.0. This flaw exists specifically within the Patient REST API endpoint, where an authenticated user with API access can exploit the `_sort` parameter to execute arbitrary SQL queries. The root cause is improper validation and sanitization of user-supplied input used in SQL `ORDER BY` clauses, which allows malicious actors to manipulate database queries.
#Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #SQLInjection #DDoS https://cvetodo.com/cve/CVE-2026-24908
Post summary
The post discloses an SQL injection flaw in OpenEMR’s Patient REST API that allows authenticated API users to execute arbitrary SQL queries via the `_sort` parameter.