Authentication Bypass in OpenEMR by OpenEMR Inc.
CVE-2026-67611
Key Information:
Badges
What is CVE-2026-67611?
OpenEMR versions until 8.2.0 exhibit a vulnerability that allows attackers with valid user credentials to bypass multi-factor authentication. This is accomplished by exploiting an unauthenticated client registration endpoint as part of the OAuth2 password grant flow. By registering an OAuth2 client without authentication, attackers can leverage the password grant method to obtain an API access token, effectively circumventing the standard authentication interface and any multi-factor authentication measures that are supposed to be in place.
Affected Version(s)
openemr 0 <= 8.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
