CVE-2026-34051: OpenEMR has Improper ACL On Import/Export Popup
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and export actions through direct request manipulation despite UI restrictions. This can lead to unauthorized data access, bulk data extraction, and manipulation of system data. Version 8.0.0.3 contains a fix.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34051?
CVE-2026-34051 has been classified as a medium severity vulnerability due to improper access control allowing unauthorized users to access sensitive functionalities.
How do I fix CVE-2026-34051?
To fix CVE-2026-34051, upgrade OpenEMR to version 8.0.0.3 or later, which addresses the access control issues in the Import/Export functionality.
What versions of OpenEMR are affected by CVE-2026-34051?
CVE-2026-34051 affects all versions of OpenEMR prior to 8.0.0.3.
What risks does CVE-2026-34051 pose to users?
CVE-2026-34051 can allow unauthorized users to perform import and export operations, potentially leading to unauthorized access to sensitive health data.
Is there a workaround for CVE-2026-34051?
There are no official workarounds for CVE-2026-34051; upgrading to the latest version is the recommended solution.