SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-67611

HIGH · CVSS 8.1 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

OpenEMR versions up to 8.2.0 are vulnerable to an authentication bypass that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting an unauthenticated client registration endpoint. This vulnerability enables attackers to register an OAuth2 client and obtain an API access token, undermining the security of the system. Organizations using OpenEMR should prioritize patching this vulnerability to protect against potential unauthorized access and data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67611
Severity
HIGH
CVSS
8.1
EPSS
0.33%
Exchange

Original NVD Description

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.

Related CVEs

Other vulnerabilities affecting the same vendor(s)