Critical RCE Vulnerability in OpenEMR Exposes Servers to Attacks

Critical RCE Vulnerability in OpenEMR Exposes Servers to Attacks

First seen 4 Aug 2026, 14:51 UTC Mallory.Aicvefeed.iojivasecurity.comwww.vulncheck.com 90% similarity 72.0

Article Content

Browse articles
ThreatCluster

A critical remote code execution vulnerability, CVE-2026-39932, affects OpenEMR versions up to 8.2.0. The flaw arises from an unsafe eval() call in the document category tree component, allowing attackers to execute arbitrary PHP code stored in the categories database table. This vulnerability can be exploited by authenticated administrators to alter the id column type to VARCHAR and insert malicious PHP payloads. The exploit can be triggered by both authenticated and unauthenticated page activities, leading to command execution as the web server user. The CVSS scores for this vulnerability are 9.4 (CVSS 4.0) and 9.1 (CVSS 3.1). Users are advised to upgrade to OpenEMR version 8.2.1 or later and review their database integrity and access controls. The vulnerability was publicly reported on August 3, 2026.

Key Points: • CVE-2026-39932 allows RCE in OpenEMR versions up to 8.2.0 due to eval() injection. • Attackers can execute commands as the web server user by exploiting the vulnerability. • Immediate upgrade to OpenEMR 8.2.1 or later is recommended to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-08-03
CVE-2026-39932 published
A critical RCE vulnerability in OpenEMR was disclosed, affecting versions up to 8.2.0.
Mallory.Ai

Community

Browse all →

Tracked Entities in This Story