Path Traversal Vulnerability in OpenEMR by OpenEMR Limited
CVE-2026-76614

5.3MEDIUM

Key Information:

Vendor

Openemr

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76614?

OpenEMR versions prior to 8.3.0 are susceptible to a path traversal vulnerability within the EDI archive restore function. This issue arises when the archrestore_sel POST parameter is used without proper sanitization, allowing an authenticated user with EOB Data Entry permissions to exploit this weakness. The inherent flaw enables attackers to probe system paths, leading to potential information disclosure, as the application provides varying response messages based on the existence of the target paths. This could allow malicious users to discern sensitive filesystem information, thus compromising system security.

Affected Version(s)

openemr 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams from Pellera Technologies
VulnCheck
.