CVE-2026-44715
Last modified
CVE-2026-44715 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| openmrs | org.openmrs.module:legacyui-api | < 1.23.0; >= 2.0.0, < 2.10.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-44715?
How severe is CVE-2026-44715?
How do I fix CVE-2026-44715?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4471A weakness has been identified in itsourcecode Online Frozen…9.8
- CVE-2026-44710pam_usb provides hardware authentication for Linux using ord…4.6
- CVE-2026-44711pam_usb provides hardware authentication for Linux using ord…7.9
- CVE-2026-44712pam_usb provides hardware authentication for Linux using ord…8.2
- CVE-2026-44713pam_usb provides hardware authentication for Linux using ord…8.8
- CVE-2026-44714The bitcoinj library is a Java implementation of the Bitcoin…7.5
- CVE-2026-44716Pipecat is an open-source Python framework for building real…7.5
- CVE-2026-44717MCP Calculate Server is a mathematical calculation service b…9.8
- CVE-2026-44718Mathesar is a web application that makes working with Postgr…5.3
- CVE-2026-44719Mathesar is a web application that makes working with Postgr…5.3
- CVE-2026-4472A security vulnerability has been detected in itsourcecode O…9.8
- CVE-2026-44720OpenLearnX is an open-source, decentralized learning and ass…6.9
Are you affected by CVE-2026-44715?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
