CVE-2026-25146General(open-emr / openemr)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch open-emr openemr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary money movement or broad account takeover of payment gateway APIs. This vulnerability is fixed in 8.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openemr

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-03); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openemr

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-03: 3Mentions · 2026-03-04: 2Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 103-0303-04
Signal classification3 categories
General
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-033
General2Patch1
2026-03-042
Disclosure2
Full discourse5 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25146 - Critical OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_k... https://www.thehackerwire.com/vulnerability/CVE-2026-25146/ https://t.co/OIFrMbjoSG

    Post summary

    A new critical vulnerability (CVE-2026-25146) affecting OpenEMR versions 5.0.2 to before 8.0.0 has been disclosed, but no PoC, exploit, patch, or active exploitation details are provided in the text.

    0001037
    121 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25146 OpenEMR Payment Gateway API Key Exposure Vulnerability in Versions 5.0.2 to 8.0.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25146

    Post summary

    The text announces CVE‑2026‑25146, a vulnerability exposing API keys in OpenEMR versions 5.0.2 to 8.0.0, without providing exploitation details or mitigation information.

    0001047
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-25146 OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths wh… https://www.cve.org/CVERecord?id=CVE-2026-25146 ----- Traducción: CVE-2026-25146 Ope… http://infoflow.cloud`

    Post summary

    The post briefly references CVE‑2026‑25146 for OpenEMR with a link to the CVE record, but provides no further details or actionable information.

    0000040
    55 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25146 OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths wh… https://www.cve.org/CVERecord?id=CVE-2026-25146

    Post summary

    The text references CVE-2026-25146 affecting OpenEMR versions 5.0.2 to before 8.0.0 but provides no further technical or actionable details.

    00000625
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25146: CRITICAL] Update to OpenEMR 8.0.0 to fix a security flaw where gateway_api_key secret value is exposed, enabling potential money movement or account takeover risks.#cve,CVE-2026-25146,#cybersecurity https://cvefind.com/CVE-2026-25146

    Post summary

    OpenEMR 8.0.0 update addresses CVE-2026-25146 by fixing an exposed gateway_api_key secret that could allow money movement or account takeover.

    0000055
    593 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen-emropenemr---

Explore more