Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-67611

Опубликовано: 03 авг. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.

EPSS

Процентиль: 25%
0.00329
Низкий

8.1 High

CVSS3

Дефекты

CWE-308

Связанные уязвимости

CVSS3: 8.1
github
3 дня назад

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.

EPSS

Процентиль: 25%
0.00329
Низкий

8.1 High

CVSS3

Дефекты

CWE-308