Skip to main content
CRITICAL

CVE-2026-24849

CVSS v3

9.9

CRITICAL

EPSS Score

2.2 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. Any authenticated user (regardless of privilege level) can exploit this vulnerability to read sensitive files. Version 7.0.4 patches the issue.

Technical details

Published
2026-02-25
Last Modified
2026-02-25
Exploit-DB
EDB-52610

Frequently asked questions

What is CVE-2026-24849?

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. Any authenticated user (regardless of privilege level) can exploit this vulnerability to read sensitive files. Version 7.0.4 patches the issue.

Is CVE-2026-24849 actively exploited?

Active exploitation of CVE-2026-24849 has not been confirmed. Its EPSS score was 2.2% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-24849?

CVE-2026-24849 has a CVSS v3 base score of 9.9 (CRITICAL severity).

Is CVE-2026-24849 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key