CVE-2026-25745 | OpenEMR up to 8.0.0 Message Update authorization (GHSA-jm78-x5p7-52qh / EUVD-2026-12952)
A vulnerability was found in OpenEMR up to 8.0.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Message Update Handler. Executing a manipulation can lead to authorization bypass.
This vulnerability is handled as CVE-2026-25745. The attack can be executed remotely. There is not any exploit available.
Applying a patch is advised to resolve this issue.