Path Traversal Vulnerability in OpenEMR by OpenEMR Limited
CVE-2026-76614
5.3MEDIUM
What is CVE-2026-76614?
OpenEMR versions prior to 8.3.0 are susceptible to a path traversal vulnerability within the EDI archive restore function. This issue arises when the archrestore_sel POST parameter is used without proper sanitization, allowing an authenticated user with EOB Data Entry permissions to exploit this weakness. The inherent flaw enables attackers to probe system paths, leading to potential information disclosure, as the application provides varying response messages based on the existence of the target paths. This could allow malicious users to discern sensitive filesystem information, thus compromising system security.
Affected Version(s)
openemr 0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Williams from Pellera Technologies
VulnCheck
