OpenEMR Arbitrary File Read Vulnerability
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 10epss 2.2%
from disclosure to weapon101 days
Published on NVDFeb 25
1st PoC+101d
exploitation probability
2.2%top 19% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. Any authenticated user (regardless of privilege level) can exploit this vulnerability to read sensitive files. Version 7.0.4 patches the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
openemr · openemrpublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/52610unverifiedgithubgithub.com/doany1/CVE-2026-24849★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.