VYPR
High severity8.1OSV Advisory· Published Aug 3, 2026· Updated Sep 9, 2026

CVE-2026-67610

CVE-2026-67610

Description

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Openemr/Openemrllm-fuzzy2 versions
    <=8.2.0+ 1 more
    • (no CPE)range: <=8.2.0
    • (no CPE)range: v8_2_0, v3_0_1, v3_0_0, …

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.