Path Traversal Vulnerability in OpenMRS Core Electronic Medical Record System
CVE-2026-40075
8.2HIGH
What is CVE-2026-40075?
The OpenMRS Core electronic medical record system is susceptible to a path traversal vulnerability via the /openmrs/moduleResources/{moduleid} endpoint. In the affected versions, user input is improperly handled, enabling attackers to traverse directories and access sensitive files on the server, such as the /etc/passwd file. This vulnerability is particularly concerning as it is not protected by authentication mechanisms due to the nature of its functionality. Additionally, exploitation can occur on deployments running vulnerable versions of Apache Tomcat, underscoring the importance of updating to patched versions or securing the system against such attacks.
Affected Version(s)
openmrs-core <= 2.7.8 <= 2.7.8
openmrs-core >= 2.8.0, <= 2.8.5 <= 2.8.0, 2.8.5
