cvefeed.io Critical RCE Vulnerability in OpenEMR Exposes Servers to Attacks
Article Content
- •CVE-2026-39932 allows RCE in OpenEMR versions up to 8.2.0 due to eval() injection.
- •Attackers can execute commands as the web server user by exploiting the vulnerability.
- •Immediate upgrade to OpenEMR 8.2.1 or later is recommended to mitigate risks.
A critical remote code execution vulnerability, CVE-2026-39932, affects OpenEMR versions up to 8.2.0. The flaw arises from an unsafe eval() call in the document category tree component, allowing attackers to execute arbitrary PHP code stored in the categories database table. This vulnerability can be exploited by authenticated administrators to alter the id column type to VARCHAR and insert malicious PHP payloads. The exploit can be triggered by both authenticated and unauthenticated page activities, leading to command execution as the web server user. The CVSS scores for this vulnerability are 9.4 (CVSS 4.0) and 9.1 (CVSS 3.1). Users are advised to upgrade to OpenEMR version 8.2.1 or later and review their database integrity and access controls. The vulnerability was publicly reported on August 3, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Ubuntu and CVE-2026-39931 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Confidentiality Flaw in FreeIPA's idp-add Command Exposes Credentials A vulnerability identified as CVE-2026-79678 in FreeIPA's idp-add command allows any authenticated IPA principal to access environment variables and cause denial of service through memory exhaustion. The flaw arises from insufficient validation of input parameters, allowing unauthorized access to sensitive data in…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…