CVE-2026-25147 | OpenEMR up to 7.x portal_payment.php pid authorization
A vulnerability was found in OpenEMR up to 7.x and classified as critical. This impacts an unknown function of the file portal/portal_payment.php. Such manipulation of the argument pid leads to authorization bypass.
This vulnerability is referenced as CVE-2026-25147. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.