CVE-2026-2991Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access token before authenticating a user. This makes it possible for unauthenticated attackers to log in as any patient registered on the system by providing only their email address and an arbitrary value for the access token, bypassing all credential verification. The attacker gains access to sensitive medical records, appointments, prescriptions, and billing information (PII/PHI breach). Additionally, authentication cookies are set before the role check, meaning the auth cookies for non-patient users (including administrators) are also set in the HTTP response headers, even though a 403 response is returned.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-18); latest day: 2
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-03-18: 4Mentions · 2026-04-04: 2Technical Details · 2026-03-18: 4Technical Details · 2026-04-04: 203-1804-04
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-184
Disclosure4
2026-04-042
General2
Full discourse6 posts
  • z3n@zench4n
    General

    Agent systems amplify threats via chained exploits. A single auth bypass (like CVE-2026-2991 in KiviCare) can cascade into privilege escalation in AI orchestration layers.

    Post summary

    The text merely situates CVE-2026-2991 as an authentication bypass that can cascade into privilege escalation, without providing evidence of exploitation, PoC, or mitigation.

    1000026
    1.4K followersView on X
  • z3n@zench4n
    General

    2/ Agent systems multiply risks through chained actions. A single compromised agent (like in CVE-2026-2991's auth bypass) can propagate through the entire system. Always model: Permission boundaries Data validation between agents Action replay vulnerabilities

    Post summary

    The excerpt notes that a single compromised agent in CVE‑2026‑2991 can cascade through the system, emphasizing the need for permission boundaries, data validation between agents, and safeguards against action replay. No specific exploit, PoC, patch, or active exploitation details are provided.

    1000031
    1.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2991 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is… https://www.cve.org/CVERecord?id=CVE-2026-2991

    Post summary

    CVE‑2026‑2991 reveals an authentication bypass flaw in the KiviCare WordPress plugin affecting all versions up to 4.1.2, with no PoC, exploitation, or mitigation details provided.

    00000116
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2991 - Critical The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patie... https://www.thehackerwire.com/vulnerability/CVE-2026-2991/ https://t.co/ybvn5bLGkc

    Post summary

    The post announces a critical authentication bypass vulnerability (CVE‑2026‑2991) in the KiviCare Clinic & Patient Management System WordPress plugin, affecting all versions up to 4.1.2, with no mention of patches, exploits, or ongoing attacks.

    0000041
    138 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2991: CRITICAL] WordPress KiviCare – Clinic & Patient Management System plugin up to v4.1.2 vulnerable to Authentication Bypass due to a flaw allowing unauthenticated attackers access to patient data...#cve,CVE-2026-2991,#cybersecurity https://cvefind.com/CVE-2026-2991

    Post summary

    The tweet announces a critical authentication bypass flaw in WordPress KiviCare plugin up to v4.1.2, enabling unauthenticated attackers to access patient data.

    0000050
    603 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-2991: KiviCare – Clinic & Patient Manag... Broken social auth logic lets attackers hijack any patient account with just an email—PHI goldmine with admin cookies le... https://zerodaysignal.com/vulnerability/CVE-2026-2991 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet reports a broken social‑auth flaw in KiviCare that permits account hijacking via email and leaks admin cookies, but it offers no proof of exploitation, patch, or PoC.

    0000052
    155 followersView on X

Explore more