OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary money movement or broad account takeover of payment gateway APIs. This vulnerability is fixed in 8.0.0.
References
Configurations
History
04 Mar 2026, 21:56
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:* | |
| References | () https://github.com/openemr/openemr/blob/6a4e18c5ec73e0c755f6f65b28a9652aded1a58b/interface/patient_file/front_payment.php#L765 - Product | |
| References | () https://github.com/openemr/openemr/blob/6a4e18c5ec73e0c755f6f65b28a9652aded1a58b/portal/portal_payment.php#L537 - Product | |
| References | () https://github.com/openemr/openemr/commit/fe6341496dc82d5b4f5a3f35891bb2e2481f3b25 - Patch | |
| References | () https://github.com/openemr/openemr/security/advisories/GHSA-2hq8-wc73-jvvq - Exploit, Vendor Advisory | |
| First Time |
Open-emr openemr
Open-emr |
03 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-03 22:16
Updated : 2026-03-04 21:56
NVD link : CVE-2026-25146
Mitre link : CVE-2026-25146
CVE.ORG link : CVE-2026-25146
JSON object : View
Products Affected
open-emr
- openemr
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
