Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
← The Naughty List

OpenEMR before 8.3.0 — two maintainer-confirmed flaws fixed in 8.3.0

HIGHCritical advisory from the vendor

Why this is on the list

Vendor-confirmed: affected range, remediation and fixed version come from the vendor or CNA advisory.

Electronic health record and practice-management system holding patient demographics, clinical notes and billing data. Flaws here bear directly on ePHI confidentiality and integrity.

Does this apply to your version?

An affected range is on record, derived from CISA's exploitation evidence rather than published by the product's vendor. Check your own release against it, or enter it in the lookup and Patient Protect will evaluate it for you.

Affected: <8.3.0 · Fixed in 8.3.0

Check your version

What to do

Update to 8.3.0 or later.

Vendor
OpenEMR
Product
OpenEMR
Affected versions
<8.3.0
Fixed in
8.3.0
First published
2026-09-08

Where this comes from

2 sources
  • VENDOR

    Source assertion: affected_range:vendor

    Read the VENDOR record
  • FIRSTSupporting intelligence

    Informs severity

    EPSS estimates a 3.7% probability that this vulnerability will be exploited in the next 30 days. It is a forecast about the vulnerability, not a statement about whether your installation is affected.

    About EPSS

How this was assessed

  • The OpenEMR maintainers published advisories in their own project repository identifying OpenEMR versions before 8.3.0 as affected by CVE-2026-39931 and CVE-2026-39932, both fixed in release 8.3.0. No exploitation of these issues is asserted by any authoritative source.

Information provided by Patient Protect's Technology Risk Ledger (“The Naughty List”) is sourced from official vendor and government advisories and is provided “as is” for informational purposes only. Inclusion on The Naughty List identifies a documented technology-security risk based on available evidence at the time of publication; it is not a finding of wrongdoing, negligence, or fault by any vendor. Patient Protect does not warrant the completeness, accuracy, or timeliness of the information. Users are solely responsible for verifying applicability to their specific environment and for their own remediation decisions. Patient Protect disclaims all liability for damages arising from the use of this information.

Do you run this?

Check your own version against the ledger — it may or may not fall inside the affected range.

Check your technology