{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/openemr-8.2.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-39932"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenEMR (8.2.0)","OpenEMR (\u003c= 8.2.0)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","remote-code-execution","healthcare","cve-2026-39931","sql-injection","web-application","vulnerability","authentication-bypass","fhir"],"_cs_type":"advisory","_cs_vendors":["OpenEMR"],"content_html":"\u003cp\u003eOpenEMR versions up to and including 8.2.0 contain a critical remote code execution vulnerability located within the document category tree component, specifically in the library/classes/Tree.class.php file. The vulnerability stems from an insecure implementation that allows an authenticated administrator to inject arbitrary PHP payloads into the categories database table. By leveraging SQL injection to alter the id column type to VARCHAR, an attacker can insert a malicious payload. This payload is subsequently executed via an unsanitized eval() function call whenever the CategoryTree component is instantiated. Because this component is used across various parts of the application, including pages accessible to unauthenticated users or those with low privileges, a successful exploit results in arbitrary command execution under the context of the web server user. This vulnerability requires administrative access to initiate, but the impact extends to full system compromise from the web server's privilege level.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the OpenEMR instance with administrative privileges.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the document category tree management interface.\u003c/li\u003e\n\u003cli\u003eAttacker executes a crafted SQL injection payload to alter the schema of the categories database table, changing the id column type to VARCHAR.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a malicious PHP code snippet as a record into the categories table.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the vulnerability by navigating to a page (including unauthenticated endpoints) that invokes the CategoryTree class.\u003c/li\u003e\n\u003cli\u003eThe application performs an unsanitized eval() call on the injected database content.\u003c/li\u003e\n\u003cli\u003eThe web server process executes the attacker-supplied PHP payload.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution as the web server user for further post-exploitation activity.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote command execution on the host running the OpenEMR instance. This compromises the integrity and confidentiality of the electronic medical records data stored within the application and grants the attacker a foothold on the internal network segment hosting the web server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all OpenEMR instances to the latest secure version addressing this vulnerability.\u003c/li\u003e\n\u003cli\u003eImplement strict administrative access controls to limit the number of users capable of modifying database-driven configurations.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious database query patterns, specifically those attempting to alter schema definitions or modify core application tables.\u003c/li\u003e\n\u003cli\u003ePerform code review or implement file integrity monitoring on library/classes/Tree.class.php to detect unauthorized modifications.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-03T20:06:27Z","date_published":"2026-08-03T18:05:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-openemr-rce/","summary":"OpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.","title":"Remote Code Execution in OpenEMR Document Category Tree","url":"https://feed.craftedsignal.io/briefs/2026-08-openemr-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenEMR (8.2.0)","version":"https://jsonfeed.org/version/1.1"}