
CVE-2026-67610 OpenEMR Improper OAuth2 client registration could allow malicious clients to access FHIR resources after approval in affected healthcare deployments Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-08-03/TIER_2_CVE-2026-67610.md #CyberSecurity #HealthcareCybersecurity #VulnerabilityManagement
Post summary
This post announces CVE‑2026‑67610, describing how improper OAuth2 client registration in OpenEMR can give malicious clients access to FHIR resources after approval, and points to a full analysis report.
