PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-55081 dhis2 CVE debrief

The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization, allowing a crafted `scope` value to be rendered as active HTML or JavaScript. This vulnerability affects DHIS2 versions 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged. Users of these versions should assess and apply patches.

Vendor
dhis2
Product
dhis2-core
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Users of DHIS2 versions 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged, should assess and apply patches. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability and apply patches or mitigations as needed.

Technical summary

The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization. A crafted `scope` value could be rendered as active HTML or JavaScript in the OpenAPI documentation page. An attacker able to get a user to open a crafted OpenAPI HTML URL could execute JavaScript in that user's browser in the DHIS2 origin. Affected versions include DHIS2 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged.

Defensive priority

High priority due to potential for JavaScript execution in user's browser.

Recommended defensive actions

  • Apply patches: upgrade to DHIS2 2.42.5.1, 2.43.0.1, or later versions.
  • Inventory and verify DHIS2 installations for exposure.
  • Monitor for suspicious OpenAPI usage.
  • Educate users about safe URL practices.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

Evidence from official CVE and NVD sources indicate a high-severity vulnerability with potential for JavaScript execution in user's browser. Limited details on exploitability and attack surface. Defenders should verify DHIS2 installations, review OpenAPI usage, and monitor for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T19:17:10.950Z and has not been modified since then.