CVE-2026-33934
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in portal/sign/lib/show-signature.php that allows any authenticated patient portal user to retrieve the drawn signature image of any staff member by supplying an arbitrary user value in the POST body. The companion write endpoint (save-signature.php) was already hardened against this same issue, but the read endpoint was not updated to match.
Version 8.0.0.3 patches the issue.
MEDIUM · CVSS 4.3
EPSS 0.00056
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0