VYPR
Unrated severityOSV Advisory· Published Aug 3, 2026· Updated Aug 3, 2026

OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access

CVE-2026-67610

Description

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system.

Affected products

2
  • Openemr/OpenemrOSV2 versions
    v8_2_0, v3_0_1, v3_0_0, …+ 1 more
    • (no CPE)range: v8_2_0, v3_0_1, v3_0_0, …
    • (no CPE)range: <=8.2.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.