CVE-2026-24898 | OpenEMR up to 7.x MedEx Callback Endpoint callback_key improper authentication (GHSA-qwff-3mw7-7rc7)
A vulnerability, which was classified as critical, has been found in OpenEMR up to 7.x. The affected element is an unknown function of the component MedEx Callback Endpoint. The manipulation of the argument callback_key leads to improper authentication.
This vulnerability is traded as CVE-2026-24898. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.