Path Traversal Vulnerability in OpenMRS Core Electronic Medical Record System
CVE-2026-40075

8.2HIGH

Key Information:

Vendor

Openmrs

Vendor
CVE Published:
5 May 2026

What is CVE-2026-40075?

The OpenMRS Core electronic medical record system is susceptible to a path traversal vulnerability via the /openmrs/moduleResources/{moduleid} endpoint. In the affected versions, user input is improperly handled, enabling attackers to traverse directories and access sensitive files on the server, such as the /etc/passwd file. This vulnerability is particularly concerning as it is not protected by authentication mechanisms due to the nature of its functionality. Additionally, exploitation can occur on deployments running vulnerable versions of Apache Tomcat, underscoring the importance of updating to patched versions or securing the system against such attacks.

Affected Version(s)

openmrs-core <= 2.7.8 <= 2.7.8

openmrs-core >= 2.8.0, <= 2.8.5 <= 2.8.0, 2.8.5

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.