Unauthenticated Token Disclosure in OpenEMR Affects Health Records Management
CVE-2026-24898
What is CVE-2026-24898?
OpenEMR, a widely used open-source electronic health records platform, is affected by a critical vulnerability that allows unauthorized users to access sensitive MedEx API tokens. This security flaw arises from a misconfigured endpoint that bypasses vital authentication processes, exposing practice information and enabling potential third-party service compromises. With this vulnerability, attackers can not only extract sensitive personal health information (PHI) but also perform unauthorized actions on the MedEx platform, leading to serious implications for patient data security and HIPAA compliance. The issue has been addressed in version 8.0.0, which is crucial for all users to adopt to maintain system integrity and protect patient data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openemr < 8.0.0
