Path Traversal Vulnerability in OpenEMR by OpenEMR
CVE-2026-40506

7HIGH

Key Information:

Vendor

Openemr

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-40506?

OpenEMR versions prior to 8.2.0 are susceptible to a path traversal vulnerability that arises from improper validation of the db GET parameter in the standard_tables_manage.php interface. Attackers can exploit this vulnerability by injecting a traversal sequence into the db parameter, which the temp_dir_cleanup() function concatenates with the PHP temporary directory path. This can lead to arbitrary recursive directory deletion, especially if the attacker constructs a malicious URL that leverages an open redirect in dicom_frame.php. As a result, authenticated Superuser sessions can be compromised, leading to significant data loss and potential system disruption.

Affected Version(s)

openemr 0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams from Pellera Technologies
.