Access Control Flaw in OpenEMR's ACL Function
CVE-2026-33302
What is CVE-2026-33302?
OpenEMR, a widely used open source electronic health records management application, suffers from a significant access control vulnerability prior to version 8.0.0.2. The affected ACL function, AclMain::zhAclCheck(), is inadequately designed, allowing users in groups with 'allow' permissions to gain access even when explicitly denied. This flaw prevents administrators from effectively revoking user or group access. Consequently, if a user belongs to a group with 'allow' permissions, access is granted despite any explicit 'deny' settings. The remediation was included in the update to version 8.0.0.2, which addresses this critical design oversight.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openemr < 8.0.0.2
