CVE-2026-76614: OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore

Published Aug 19, 2026
·
Updated

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestoresel POST parameter is passed to the archive restore handler without sanitization for path traversal sequences. The handler checks whether the supplied path exists on the filesystem, and the differing response messages leak whether the target path exists. An authenticated user with EOB Data Entry permissions can probe arbitrary filesystem paths on the server to determine file existence.

Affected Software

1 affected component
OpenEMR OpenEMR<8.3.0

Event History

Aug 19, 2026
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated to OpenEMR and have EOB Data Entry permissions. Unauthenticated users are not described as able to exploit it.

2

What information can an attacker obtain?

The attacker can probe arbitrary filesystem paths and use differing application responses to determine whether a target path exists. The described impact is file-existence disclosure, not reading file contents or modifying files.

3

Are systems on the default configuration affected?

The available information does not state whether EOB Data Entry permissions are assigned by default. Exposure depends on having an authenticated account with that permission.

4

How can I determine whether an instance is vulnerable?

OpenEMR versions before 8.3.0 are affected. A vulnerable instance allows the EDI archive restore function's archrestore_sel POST parameter to reach the restore handler without path-traversal sanitization.

5

What should be done if upgrading cannot happen immediately?

Restrict EOB Data Entry permissions to only trusted users, since that permission is required for exploitation. Monitor use of the EDI archive restore function and investigate attempts to submit path-traversal sequences through the archrestore_sel parameter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203