CVE Explorer
CVE-2026-25927
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the DICOM viewer state API (e.g. upload or state save/load) accepts a document ID (`doc_id`) without verifying that the document belongs to the current user’s authorized patient or encounter. An authenticated user can read or modify DICOM viewer state (e.g. annotations, view settings) for any document by enumerating document IDs. Version 8.0.0 fixes the issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"openemr","vendor":"openemr","versions":[{"status":"affected","version":"< 8.0.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c58cfc4a2cda7915f20c2529a47c5330be0e4e5981e3e721e2bd653c0a9fcb5f · sha256:b2393e2a80eea39a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c58cfc4a2cda7915f20c2529a47c5330be0e4e5981e3e721e2bd653c0a9fcb5f · sha256:b2393e2a80eea39a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c58cfc4a2cda7915f20c2529a47c5330be0e4e5981e3e721e2bd653c0a9fcb5f · sha256:b2393e2a80eea39a… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/openemr/openemr/security/advisories/GHSA-qj9f-x7v2-hrr7","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openemr/openemr/security/advisories/GHSA-qj9f-x7v2-hrr7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c58cfc4a2cda7915f20c2529a47c5330be0e4e5981e3e721e2bd653c0a9fcb5f · sha256:b2393e2a80eea39a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.