CVE-2026-39932: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrato
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the id column type to VARCHAR and insert a malicious PHP payload, which is then executed via an unsanitized eval() call whenever any page instantiates CategoryTree, including unauthenticated and low-privilege pages, resulting in command execution as the web server user.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-39932
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-39932 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for OpenEMR
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-67612: OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient port…nvd · 2026-08-03
- highCVE-2026-67611: OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers wi…nvd · 2026-08-03
- highCVE-2026-67610: OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic …nvd · 2026-08-03
- highCVE-2026-39931: OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup conf…nvd · 2026-08-03
More from NVD Recent CVEs
- unknownCVE-2026-69249: python-cryptography is a package designed to expose cryptographic primitives and recipes to Py…2026-08-03
- unknownCVE-2026-69248: cryptography is a package designed to expose cryptographic primitives and recipes to Python de…2026-08-03
- unknownCVE-2026-69247: cryptography is a package designed to expose cryptographic primitives and recipes to Python de…2026-08-03
- unknownCVE-2026-67977: An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2…2026-08-03
- unknownCVE-2026-67975: Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index s…2026-08-03