CVE-2026-34053
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint interface/forms/procedureorder/handledeletions.php allows any authenticated user, regardless of role, to irreversibly delete procedure orders, answers, and specimens belonging to any patient in the system. Version 8.0.0.3 patches the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34053.json, https://github.com/openemr/openemr/commit/7a16b731af7d34ffd92155fe2a5692fa1a67858e, https://github.com/openemr/openemr/releases/tag/v800_3, https://github.com/openemr/openemr/security/advisories/GHSA-3vvq-pfq6-pw98, https://nvd.nist.gov/vuln/detail/CVE-2026-34053
