Skip to main content
CRITICAL

CVE-2026-32238

CVSS v3

9.1

CRITICAL

EPSS Score

2.6 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the backup functionality. Version 8.0.0.2 fixes the issue.

Technical details

Published
2026-03-19

Frequently asked questions

What is CVE-2026-32238?

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the backup functionality. Version 8.0.0.2 fixes the issue.

Is CVE-2026-32238 actively exploited?

Active exploitation of CVE-2026-32238 has not been confirmed. Its EPSS score was 2.6% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-32238?

CVE-2026-32238 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2026-32238 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key