← Back to browse · API

CVE-2026-24849

Severity
CRITICAL
CVSS
10.0
EPSS
0.02164
Risk score
40.76
CISA KEV
No
PoC
Yes
Published
2026-02-25
Modified
2026-02-25
First seen
2026-08-07
Aliases
EUVD-2026-8581
Products
Open-Emr:OpenEMR < 7.0.4, unix
Sources
euvd EUVD-2026-8581
packetstorm cc2e5e2e6176161508c70050|CVE-2026-24849
packetstorm 6e1718f8b65ff16ff2c5c607|CVE-2026-24849
packetstorm ec9e25c3741724499fe8dd20|CVE-2026-24849

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. Any authenticated user (regardless of privilege level) can exploit this vulnerability to read sensitive files. Version 7.0.4 patches the issue.

References