PT-2026-62041 · Dhis2 · Dhis2

CVE-2026-55082

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions DHIS2 versions 2.37 through 2.39
Description SQL View data endpoints allow authenticated users with SQL View access to provide crafted filter values that are interpolated into generated SQL. This allows a user with SQL View execution privileges to manipulate the generated SQL for filters and potentially access data outside the intended result set.
Recommendations Update DHIS2 version 2.37 to the 2026-06-09 EOS security update. Update DHIS2 version 2.38 to the 2026-06-09 EOS security update. Update DHIS2 version 2.39 to the 2026-06-09 EOS security update.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55082
GHSA-3288-CM98-664F

Affected Products

Dhis2