CVE-2026-67611
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.53%
- CWE
- CWE-308
- Published
- 2026-08-03
- Last modified
- 2026-08-14
Affected products
- openemr openemr
Weakness type
Related vulnerabilities
- CVE-2026-58240 — Missing Authentication check in SAP NetWeaver (Message Server)
- CVE-2026-85590 — phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
- CVE-2026-56022 — Webmin MFA bypass
- CVE-2024-27928 — Vantage6: 2FA can be circumvented with hacked email access
- CVE-2026-45749 — Termix's TOTP two-factor authentication can be disabled or bypassed using only the account password
- CVE-2026-33550 — SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length...
- CVE-2025-64103 — Zitadel Bypass Second Authentication Factor
- CVE-2025-42959 — Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476