Sploitus

CVE-2026-67610

No indexed exploits for CVE-2026-67610 yet

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system.

Affected products
Openemr
Fix
Available
CVSS 4.0
8.6 HIGH
CVSS 3.1
8.1 HIGH
EPSS
0.3% (25th percentile)
Weakness
CWE-306
NVD status
Received
Published
2026-08-03
CVE-2026-67610 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-67610 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-67610 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.