CVE-2026-44715 is a high-severity vulnerability in OpenMRS, an open-source electronic medical record system platform. An authenticated user can trigger administrative DWR services, specifically the `startHl7ArchiveMigration` method, which should be restricted to admin-level accounts. The issue was patched in versions 1.23.0 and 2.10.0. This vulnerability allows potential unauthorized access and disruption [truncated]
A critical remote code execution vulnerability exists in OpenMRS Core versions 2.7.0 through 2.7.8 and 2.8.0 through 2.8.5. The ConceptReferenceRangeUtility.evaluateCriteria() method evaluates database-stored criteria strings as Apache Velocity templates without sandboxing. The VelocityEngine is initialized with only logging properties and noSecureUberspector, leaving the default UberspectImpl in place, w [truncated]