A critical remote code execution flaw, tracked as CVE-2026-39932, affects OpenEMR through version 8.2.0 and stems from an unsafe eval() call in the document category tree component, specifically library/classes/Tree.class.php. The bug allows attacker-controlled PHP code stored in the categories database table to be executed when the application instantiates CategoryTree, turning a database-level compromise into code execution on the server. The issue has been rated 9.4 (CVSS 4.0) and 9.1 (CVSS 3.1).
Public reporting says an authenticated administrator can chain arbitrary SQL execution to alter the id column type to VARCHAR and insert a malicious PHP payload, which is then triggered by both authenticated and unauthenticated page activity that loads the category tree. Successful exploitation can lead to operating system command execution as the web server user. Defenders are advised to upgrade to OpenEMR 8.2.1 or later and review database integrity, input sanitization, administrative access, and signs of unauthorized command execution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A critical remote code execution vulnerability affecting OpenEMR through version 8.2.0 was published as CVE-2026-39932. The flaw is in the document category tree component, where an unsanitized eval() call in Tree.class.php can execute attacker-controlled PHP code stored in the categories table.
The vulnerability advisory recommends updating OpenEMR to version 8.2.1 or later to address CVE-2026-39932. Additional remediation guidance includes reviewing database integrity, sanitizing inputs, restricting administrative privileges, and monitoring for unauthorized command execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcejivasecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.