CVE-2026-67611: OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the expos
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-67611
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-67611 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for OpenEMR
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-67612: OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient port…nvd · 2026-08-03
- highCVE-2026-67610: OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic …nvd · 2026-08-03
- criticalCVE-2026-39932: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category …nvd · 2026-08-03
- highCVE-2026-39931: OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup conf…nvd · 2026-08-03
More from NVD Recent CVEs
- unknownCVE-2026-69249: python-cryptography is a package designed to expose cryptographic primitives and recipes to Py…2026-08-03
- unknownCVE-2026-69248: cryptography is a package designed to expose cryptographic primitives and recipes to Python de…2026-08-03
- unknownCVE-2026-69247: cryptography is a package designed to expose cryptographic primitives and recipes to Python de…2026-08-03
- unknownCVE-2026-67977: An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2…2026-08-03
- unknownCVE-2026-67975: Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index s…2026-08-03