{"apiVersion":"1.0","identifier":"CVE-2026-40506","description":"OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without validation to temp_dir_cleanup(), which joins the value to the PHP temporary directory path and recursively deletes the resulting directory. Attackers can supply a traversal sequence in the db parameter to resolve outside the intended temporary directory, and by chaining this with an open redirect in dicom_frame.php, an unauthenticated attacker can deliver a crafted URL that triggers arbitrary recursive directory deletion within an authenticated Superuser-s session.","publishedAt":"2026-08-17T21:16:44","lastModifiedAt":"2026-08-18T15:16:53","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-40506","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","epssProbability":0.00448,"riskScore":0.68,"affectedProduct":"OpenEMR","affectedVersions":"<8.2.0","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-40506","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-40506","en":"https://www.redsauce.net/en/cves/CVE-2026-40506","fr":"https://www.redsauce.net/fr/cves/CVE-2026-40506","pt":"https://www.redsauce.net/pt/cves/CVE-2026-40506","de":"https://www.redsauce.net/de/cves/CVE-2026-40506","sk":"https://www.redsauce.net/sk/cves/CVE-2026-40506","el":"https://www.redsauce.net/el/cves/CVE-2026-40506"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-40506"}}