Access Control Flaw in OpenEMR's ACL Function
CVE-2026-33302

7.3HIGH

Key Information:

Vendor

Openemr

Status
Vendor
CVE Published:
19 March 2026

What is CVE-2026-33302?

OpenEMR, a widely used open source electronic health records management application, suffers from a significant access control vulnerability prior to version 8.0.0.2. The affected ACL function, AclMain::zhAclCheck(), is inadequately designed, allowing users in groups with 'allow' permissions to gain access even when explicitly denied. This flaw prevents administrators from effectively revoking user or group access. Consequently, if a user belongs to a group with 'allow' permissions, access is granted despite any explicit 'deny' settings. The remediation was included in the update to version 8.0.0.2, which addresses this critical design oversight.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

openemr < 8.0.0.2

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.