CVE-2026-40509: Openemr

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized as a URL without validation against expected path formats. An attacker can craft a URL that causes an authenticated user with Patients - Documents permissions to make authenticated requests to arbitrary OpenEMR endpoints, enabling forced logout and other state-changing actions.

Affected products

  • Openemr Openemr: before 8.3.0 (fixed in 8.3.0)

Published 2026-08-19. Last modified 2026-09-09.