CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67611

highCVSS 8.1covered by 1 sourcefirst seen 2026-08-03
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.

⚡ Watch CVE-2026-67611

Get an email if CVE-2026-67611 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-67611

CVE.org record

Embed the live status

CVE-2026-67611 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67611 status](https://www.csirts.com/badge/CVE-2026-67611)](https://www.csirts.com/cve/CVE-2026-67611)