Junglewise Threat Intelligence

CVE-2026-12207: medkey-org Medkey IDOR in PatientController

CVE-2026-12207 · Severity: medium · CVSS 4.3 · Published 2026-06-15

Executive brief

Medkey, an open-source hospital information and electronic health records system, contains a security flaw in its patient data interface. An attacker with a standard user account can access the private medical records, insurance details, and personal information of any other patient by simply changing a numeric ID in the web address. This could lead to a significant breach of protected health information and sensitive medical history.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Medkey REST API, specifically within the actionGetPatientById function of PatientController.php. The application fails to perform object-level access control checks to verify if the authenticated user has permission to view the requested patient ID. By manipulating the 'id' parameter in GET requests to the patient retrieval endpoint, a remote authenticated attacker can horizontally escalate privileges to exfiltrate sensitive medical data, including insurance policies and medical history. A public exploit (PoC) is available, and the vendor has not yet released a patch for this rolling-release software.

Affected products

  • medkey-org Medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed

Timeline

  • 2026-06-15: advisory: NVD publication date
  • 2026-06-15: disclosed: Public exploit released on GitHub

References