CVE-2026-29187: OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.php
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulnerability exists in the Patient Search functionality (/interface/new/newsearchpopup.php). The vulnerability allows an authenticated attacker to execute arbitrary SQL commands by manipulating the HTTP parameter keys rather than the values. Version 8.0.0.3 contains a patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29187?
CVE-2026-29187 is classified as a high severity vulnerability due to its potential for exploitation via SQL injection.
How do I fix CVE-2026-29187?
To resolve CVE-2026-29187, upgrade OpenEMR to version 8.0.0.3 or later.
What type of vulnerability is CVE-2026-29187?
CVE-2026-29187 is an authenticated blind boolean-based SQL injection vulnerability.
Which versions of OpenEMR are affected by CVE-2026-29187?
OpenEMR versions prior to 8.0.0.3 are affected by CVE-2026-29187.
Where can I find more information about CVE-2026-29187?
More information about CVE-2026-29187 can be found in the OpenEMR security advisories on GitHub.