CVE-2026-25146
OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary money movement or broad account takeover of payment gateway APIs. This vulnerability is fixed in 8.0.0.
- Affected products
- Openemr
- Open-emr Openemr
- < 8.0.0
- Fix
- Available
- CVSS 3.1
- 9.6 CRITICAL
- EPSS
- 0.4% (37th percentile)
- Weakness
- CWE-200
- NVD status
- Analyzed
- Published
- 2026-03-03
CVE-2026-25146 at NVD
No indexed exploits for CVE-2026-25146 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-25146 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.