PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-55082 dhis2 CVE debrief

The CVE-2026-55082 vulnerability allows authenticated users with SQL View access in DHIS2 to inject SQL by providing crafted filter values. This could enable them to manipulate SQL generated for SQL View filters and potentially access data outside the intended SQL View result set. The vulnerability has a CVSS score of 8.7 and is considered high-severity. It affects DHIS2 release lines 2.37, 2.38, and 2.39 before the 2026-06-09 EOS security updates. The vulnerability was patched by the 2026-06-09 EOS security updates for these release lines.

Vendor
dhis2
Product
dhis2-core
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Organizations using DHIS2 versions 2.37, 2.38, or 2.39 before the 2026-06-09 EOS security updates should prioritize patching this vulnerability. Specifically, users with SQL View access could be impacted, as they may be able to inject SQL and access unauthorized data.

Technical summary

The DHIS2 SQL View data endpoints allowed authenticated users with SQL View access to provide crafted filter values that were interpolated into generated SQL. This could enable an authenticated user to manipulate SQL generated for SQL View filters and potentially access data outside the intended SQL View result set. The vulnerability is distinct from CVE-2026-55084, which tracks a related SQL View filter column-name injection issue. The affected release lines are DHIS2 2.37, 2.38, and 2.39 before the 2026-06-09 EOS security updates. The same value-slot hardening was already present on later supported branches through DHIS2-20174 / PR #22253.

Defensive priority

High-priority patching is recommended for organizations using affected DHIS2 versions. Users with SQL View access should be particularly cautious, as they could potentially inject SQL and access unauthorized data.

Recommended defensive actions

  • Apply the 2026-06-09 EOS security updates for DHIS2 versions 2.37, 2.38, and 2.39
  • Restrict SQL View access to only necessary users
  • Monitor SQL View usage for suspicious activity
  • Consider implementing additional security controls, such as SQL injection detection and prevention tools
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-21T19:17:11.093Z and last modified on 2026-07-22T19:17:06.050Z. The NVD entry is currently Deferred. The vulnerability has a CVSS score of 8.7 and is considered high-severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T19:17:11.093Z and has not been modified since then. The NVD entry is currently Deferred.