CVE-2025-46823: OpenMRS has Vulnerability in FHIR2 Module Privileges
openmrs-module-fhir2 provides the FHIR REST API and related services for OpenMRS, an open medical records system. In versions of the FHIR2 module prior to 2.5.0, privileges were not always correctly checked, which means that unauthorized users may have been able to add or edit data they were not supposed to be able to. All implementers should update to FHIR2 2.5.0 or newer as soon as is feasible to receive a patch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46823?
CVE-2025-46823 has a medium severity due to improper privilege checks allowing unauthorized users to modify data.
How do I fix CVE-2025-46823?
To fix CVE-2025-46823, update the OpenMRS FHIR2 Module to version 2.5.0 or later.
Which versions are affected by CVE-2025-46823?
CVE-2025-46823 affects versions of the OpenMRS FHIR2 Module prior to 2.5.0.
What kind of vulnerability is CVE-2025-46823?
CVE-2025-46823 is a privilege escalation vulnerability impacting data integrity.
Who does CVE-2025-46823 affect?
CVE-2025-46823 affects users of the OpenMRS FHIR2 Module who may be at risk from unauthorized data manipulation.