CVE-2026-39932
published 2026-08-03CVE-2026-39932: OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows…
PriorityP263critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
3.68%
89.2th percentile
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the id column type to VARCHAR and insert a malicious PHP payload, which is then executed via an unsanitized eval() call whenever any page instantiates CategoryTree, including unauthenticated and low-privilege pages, resulting in command execution as the web server user.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| open-emr | openemr | < 8.2.0 | 8.2.0 |
| openemr | openemr | <= 8.2.0 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenEMR up to 8.2.0 Document Category Tree Tree.class.php eval code injection
vuldb·2026-09-01·CVSS 9.1
CVE-2026-39932 [CRITICAL] OpenEMR up to 8.2.0 Document Category Tree Tree.class.php eval code injection
A vulnerability labeled as critical has been found in OpenEMR up to 8.2.0. The impacted element is the function eval of the file library/classes/Tree.class.php of the component Document Category Tree. Executing a manipulation can lead to code injection.
This vulnerability is tracked as CVE-2026-39932. The attack can be launched remotely. No exploit exists.
GHSA
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitr
ghsa_unreviewed·2026-08-03
CVE-2026-39932 [CRITICAL] CWE-95 OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitr
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the id column type to VARCHAR and insert a malicious PHP payload, which is then executed via an unsanitized eval() call whenever any page instantiates CategoryTree, including unauthenticated and low-privilege pages, resulting in command execution as the web server user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-03
Published