OpenEMR Arbitrary File Exfiltration Vulnerability via Fax Endpoint

Vulnerability

A vulnerability allowing arbitrary file exfiltration has been identified in OpenEMR versions prior to 8.0.0. This issue resides in the fax sending endpoint, where authenticated users can read and send any file on the server, including database credentials, patient documents, system files, and source code, to an attacker-controlled phone number. The vulnerability arises because the endpoint accepts arbitrary file paths from user input and transmits them to the fax gateway without proper path validation or authorization checks.

Impact

Exploitation of this vulnerability allows for the unauthorized exfiltration of sensitive files via fax, including database credentials and patient documents.

Reproduction

To reproduce this vulnerability, an authenticated user must send a POST request to the fax sending endpoint with an arbitrary file path included in the request. The fax will be sent to the specified phone number, allowing the attacker to receive the contents of the file via fax.

Added: Feb 27, 2026, 5:19 PM
Updated: Feb 27, 2026, 5:19 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
6.2
remediation
0.0
relevance
3.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.