PatchSiren cyber security CVE debrief
CVE-2026-55081 dhis2 CVE debrief
The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization, allowing a crafted `scope` value to be rendered as active HTML or JavaScript. This vulnerability affects DHIS2 versions 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged. Users of these versions should assess and apply patches.
- Vendor
- dhis2
- Product
- dhis2-core
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Users of DHIS2 versions 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged, should assess and apply patches. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability and apply patches or mitigations as needed.
Technical summary
The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization. A crafted `scope` value could be rendered as active HTML or JavaScript in the OpenAPI documentation page. An attacker able to get a user to open a crafted OpenAPI HTML URL could execute JavaScript in that user's browser in the DHIS2 origin. Affected versions include DHIS2 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged.
Defensive priority
High priority due to potential for JavaScript execution in user's browser.
Recommended defensive actions
- Apply patches: upgrade to DHIS2 2.42.5.1, 2.43.0.1, or later versions.
- Inventory and verify DHIS2 installations for exposure.
- Monitor for suspicious OpenAPI usage.
- Educate users about safe URL practices.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
Evidence from official CVE and NVD sources indicate a high-severity vulnerability with potential for JavaScript execution in user's browser. Limited details on exploitability and attack surface. Defenders should verify DHIS2 installations, review OpenAPI usage, and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55081 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55081
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55081 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55081
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/dhis2/dhis2-core/pull/24158
-
Source reference
Unverified legacy reference
URL: https://github.com/dhis2/dhis2-core/pull/24159
-
Source reference
Unverified legacy reference
URL: https://github.com/dhis2/dhis2-core/pull/24160
-
Source reference
Unverified legacy reference
URL: https://github.com/dhis2/dhis2-core/pull/24161
-
Source reference
Unverified legacy reference
URL: https://github.com/dhis2/dhis2-core/pull/24162
-
Source reference
Unverified legacy reference
URL: https://github.com/dhis2/dhis2-core/security/advisories/GHSA-6785-hj47-c27h
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.