Disclosure
CVE-2026-25164 pertains to a critical security flaw in OpenEMR, an open-source electronic health records (EHR) and practice management system. The vulnerability arises from improper authorization checks within the REST API routes, specifically in the file `apis/routes/_rest_routes_standard.inc.php`. Prior to version 8.0.0, certain API endpoints related to documents and insurance data do not invoke the necessary access control verification (`RestConfig::request_authorization_check()`). Consequently, any valid API bearer token can access or modify sensitive patient data without regard to the token's assigned permissions.
#Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-25164
Post summary
The post discloses a critical authorization bypass in OpenEMR’s REST API that lets any bearer token read or modify sensitive data, but it does not mention a PoC, exploit, or patch.