CVE Explorer
CVE-2026-25745
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) updates by message/note ID only and does not verify that the message belongs to the current patient (or that the user is allowed to edit that patient’s notes). An authenticated user with notes permission can modify any patient’s messages by supplying another message ID. Commit 92a2ff9eaaa80674b3a934a655
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"openemr","vendor":"openemr","versions":[{"status":"affected","version":"<= 8.0.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8096861ce3e6a0cfac041a796f4963899a213f4dcb053c7a4281c73cd971bc3e · sha256:572478b3e6d67e56… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8096861ce3e6a0cfac041a796f4963899a213f4dcb053c7a4281c73cd971bc3e · sha256:572478b3e6d67e56… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8096861ce3e6a0cfac041a796f4963899a213f4dcb053c7a4281c73cd971bc3e · sha256:572478b3e6d67e56… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/openemr/openemr/commit/92a2ff9eaaa80674b3a934a6556e35e7aded5a41","tags":["x_refsource_MISC"],"url":"https://github.com/openemr/openemr/commit/92a2ff9eaaa80674b3a934a6556e35e7aded5a41"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8096861ce3e6a0cfac041a796f4963899a213f4dcb053c7a4281c73cd971bc3e · sha256:572478b3e6d67e56… · /containers/cna/references/1
{"name":"https://github.com/openemr/openemr/security/advisories/GHSA-jm78-x5p7-52qh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openemr/openemr/security/advisories/GHSA-jm78-x5p7-52qh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8096861ce3e6a0cfac041a796f4963899a213f4dcb053c7a4281c73cd971bc3e · sha256:572478b3e6d67e56… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/openemr/openemr/security/advisories/GHSA-jm78-x5p7-52qh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8096861ce3e6a0cfac041a796f4963899a213f4dcb053c7a4281c73cd971bc3e · sha256:572478b3e6d67e56… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.