OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary money movement or broad account takeover of payment gateway APIs. This vulnerability is fixed in 8.0.0.
References
Configurations
History
No history.
Information
Published : 2026-03-03 22:16
Updated : 2026-03-04 21:56
NVD link : CVE-2026-25146
Mitre link : CVE-2026-25146
CVE.ORG link : CVE-2026-25146
JSON object : View
Products Affected
open-emr
- openemr
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
