Access Control Flaw in OpenEMR's ACL Function
CVE-2026-33302
7.3HIGH
What is CVE-2026-33302?
OpenEMR, a widely used open source electronic health records management application, suffers from a significant access control vulnerability prior to version 8.0.0.2. The affected ACL function, AclMain::zhAclCheck(), is inadequately designed, allowing users in groups with 'allow' permissions to gain access even when explicitly denied. This flaw prevents administrators from effectively revoking user or group access. Consequently, if a user belongs to a group with 'allow' permissions, access is granted despite any explicit 'deny' settings. The remediation was included in the update to version 8.0.0.2, which addresses this critical design oversight.
Affected Version(s)
openemr < 8.0.0.2
