Skip to content
Critical RCE Vulnerability in OpenEMR Exposes Servers to Attacks

Critical RCE Vulnerability in OpenEMR Exposes Servers to Attacks

First seen 4 Aug 2026, 14:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 5, 2026 at 14:37 UTC
  • CVE-2026-39932 allows RCE in OpenEMR versions up to 8.2.0 due to eval() injection.
  • Attackers can execute commands as the web server user by exploiting the vulnerability.
  • Immediate upgrade to OpenEMR 8.2.1 or later is recommended to mitigate risks.

A critical remote code execution vulnerability, CVE-2026-39932, affects OpenEMR versions up to 8.2.0. The flaw arises from an unsafe eval() call in the document category tree component, allowing attackers to execute arbitrary PHP code stored in the categories database table. This vulnerability can be exploited by authenticated administrators to alter the id column type to VARCHAR and insert malicious PHP payloads. The exploit can be triggered by both authenticated and unauthenticated page activities, leading to command execution as the web server user. The CVSS scores for this vulnerability are 9.4 (CVSS 4.0) and 9.1 (CVSS 3.1). Users are advised to upgrade to OpenEMR version 8.2.1 or later and review their database integrity and access controls. The vulnerability was publicly reported on August 3, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2026-08-03
CVE-2026-39932 published
A critical RCE vulnerability in OpenEMR was disclosed, affecting versions up to 8.2.0.
Mallory.Ai

More articles in this cluster (4)

Following this threat?

Track Ubuntu and CVE-2026-39931 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed