PatchSiren

dhis2 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH dhis2 CVE published 2026-07-23

CVE-2026-55084

The DHIS2 application is vulnerable to a SQL injection attack in the SqlView API endpoint. An authenticated user with access to a SqlView can inject arbitrary SQL queries inside the `filter` parameter, allowing attackers to extract arbitrary database content using error-based SQL injection. Organizations using DHIS2 should prioritize patching this vulnerability to prevent potential database content extrac [truncated]

HIGH dhis2 CVE published 2026-07-21

CVE-2026-55082

The CVE-2026-55082 vulnerability allows authenticated users with SQL View access in DHIS2 to inject SQL by providing crafted filter values. This could enable them to manipulate SQL generated for SQL View filters and potentially access data outside the intended SQL View result set. The vulnerability has a CVSS score of 8.7 and is considered high-severity. It affects DHIS2 release lines 2.37, 2.38, and 2.39 [truncated]

HIGH dhis2 CVE published 2026-07-21

CVE-2026-55081

The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization, allowing a crafted `scope` value to be rendered as active HTML or JavaScript. This vulnerability affects DHIS2 versions 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged. Users of t [truncated]