CVE-2026-33304: OpenEMR has Authorization Bypass in Dated Reminders Log
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the dated reminders log allows any authenticated non-admin user to view reminder messages belonging to other users, including associated patient names and free-text message content, by crafting a GET request with arbitrary user IDs in the sentTo[] or sentBy[] parameters. Version 8.0.0.2 fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33304?
CVE-2026-33304 has a medium severity rating due to its potential for unauthorized access to sensitive reminder messages.
How do I fix CVE-2026-33304?
To fix CVE-2026-33304, upgrade OpenEMR to version 8.0.0.2 or later, where the authorization bypass has been resolved.
Who is affected by CVE-2026-33304?
Any authenticated non-admin user in versions prior to 8.0.0.2 of OpenEMR is affected by CVE-2026-33304.
What does CVE-2026-33304 affect?
CVE-2026-33304 affects the dated reminders log in OpenEMR, allowing unauthorized viewing of reminder messages.
Is CVE-2026-33304 an easy vulnerability to exploit?
Yes, CVE-2026-33304 is relatively easy to exploit, as it requires only authenticated access by non-admin users.