PT-2026-62041 · Dhis2 · Dhis2
CVE-2026-55082
·
Published
2026-07-21
·
Updated
2026-07-21
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
DHIS2 versions 2.37 through 2.39
Description
SQL View data endpoints allow authenticated users with SQL View access to provide crafted filter values that are interpolated into generated SQL. This allows a user with SQL View execution privileges to manipulate the generated SQL for filters and potentially access data outside the intended result set.
Recommendations
Update DHIS2 version 2.37 to the 2026-06-09 EOS security update.
Update DHIS2 version 2.38 to the 2026-06-09 EOS security update.
Update DHIS2 version 2.39 to the 2026-06-09 EOS security update.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dhis2