CVE-2026-34053: OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint interface/forms/procedureorder/handledeletions.php allows any authenticated user, regardless of role, to irreversibly delete procedure orders, answers, and specimens belonging to any patient in the system. Version 8.0.0.3 patches the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34053?
The severity of CVE-2026-34053 is classified as a high-risk vulnerability due to the lack of proper authorization in key functionality.
How do I fix CVE-2026-34053?
To fix CVE-2026-34053, upgrade to OpenEMR version 8.0.0.3 or later, where the vulnerability is addressed.
What is CVE-2026-34053?
CVE-2026-34053 is a vulnerability in OpenEMR that allows unauthorized deletion of procedure orders through a vulnerable AJAX endpoint.
Which versions are affected by CVE-2026-34053?
Versions of OpenEMR prior to 8.0.0.3 are affected by CVE-2026-34053.
What components of OpenEMR are impacted by CVE-2026-34053?
CVE-2026-34053 impacts the AJAX deletion handler in the procedure order management feature of OpenEMR.