CVE-2026-24849 is an arbitrary file read vulnerability in OpenEMR prior to version 7.0.4. The issue is present in the disposeDocument() method in EtherFaxActions.php, which allows an authenticated user to read arbitrary files from the underlying server filesystem. According to the provided information, exploitation does not depend on privilege level beyond successful authentication, meaning any valid user account can abuse the vulnerable functionality to access files outside the intended scope.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script, a README, and a license. The main file, CVE-2026-24849.py, is a standalone Python requests-based exploit for CVE-2026-24849 affecting OpenEMR versions earlier than 7.0.4. It is not part of a larger exploit framework. The exploit performs authenticated arbitrary file read against OpenEMR’s Fax/SMS EtherFax module by logging into the web application, maintaining a session, and sending GET requests to /interface/modules/custom_modules/oe-module-faxsms/index.php with parameters site, type=fax, action=download, file_path=<absolute path>, and _ACTION_COMMAND set to either disposeDoc or disposeDocument. It first primes the login page at /interface/login/login.php to obtain a session and optional CSRF token, then posts credentials to /interface/main/main_screen.php. After authentication, it probes /etc/hostname to distinguish successful exploitation from bad credentials or disabled module conditions. Capabilities include: authenticated session establishment, arbitrary absolute-path file retrieval, automatic fallback across two action names for version differences, optional local output saving, and an interactive loop for repeated file reads. The exploit is operational rather than a mere PoC because it fully automates login and data retrieval, but it does not provide a customizable post-exploitation framework. Important behavioral note: the README documents that the vulnerable server-side method calls unlink() after readfile(), so reading files writable/deletable by the web server may delete them. The exploit itself does not delete files directly; this is a side effect of the vulnerable target code. The README also states prerequisites: any valid OpenEMR account, affected version, and Fax/SMS module enabled with EtherFax selected. Overall, the repository’s purpose is to demonstrate and operationalize authenticated arbitrary file read against vulnerable OpenEMR deployments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.