CVE-2026-33304 identifies an authorization bypass vulnerability in OpenEMR versions prior to 8.0.0.2. This flaw allows any authenticated non-admin user to view reminder messages, including associated patient names and free-text content, belonging to other users by manipulating GET request parameters. Rated as a CVSS 6.5 Medium, the vulnerability has a network attack vector and low attack complexity, requiring only low privileges and no user interaction, resulting in a high confidentiality impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this issue. Organizations using affected OpenEMR versions should upgrade to 8.0.0.2 or later to remediate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.0.0.2CPE matchmatch criteria | cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.