CVE-2026-67611 Details
Description
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.
An authentication bypass vulnerability has been identified in OpenEMR versions through 8.2.0. This vulnerability allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow. The issue arises through an unauthenticated client registration endpoint, which attackers can use to register an OAuth2 client and then exchange credentials for an API access token. This bypasses the normal web interface authentication and any enforced multi-factor authentication controls.
Users are advised to disable the OAuth2 password grant option in the OpenEMR server configuration, as it is not considered secure. Additionally, the pre-authentication disclosure surface should be restricted to minimize the information available to potential attackers.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jivasecurity.com/writeups/openemr-preauth-disclosure-password-grant | [email protected] | ExploitMitigationThird Party Advisory |
| https://www.vulncheck.com/advisories/openemr-oauth2-password-grant-authentication-bypass-via-smart-configuration | [email protected] | ExploitThird Party AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-308 | Use of Single-factor Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| open-emr openemr | <= 8.2.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | Initial Analysis | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |