OpenAPI HTML Endpoint Vulnerability in DHIS2 by DHIS2
CVE-2026-55081

7.3HIGH

Key Information:

Vendor

Dhis2

Vendor
CVE Published:
21 July 2026

What is CVE-2026-55081?

The DHIS2 information system is susceptible to a Cross-Site Scripting vulnerability through its OpenAPI HTML endpoint. This issue arises when the scope query parameter is reflected in the generated HTML without adequate sanitization. An attacker can exploit this flaw by crafting a malicious URL that, when accessed by an unsuspecting user, executes JavaScript code in their browser within the DHIS2 environment. This could lead to unauthorized actions or data exposure. The vulnerability affects DHIS2 versions 2.42 and 2.43 prior to the security patch on June 9, 2026. Users are encouraged to upgrade to patched versions 2.42.5.1, 2.43.0.1, or later to mitigate this risk.

Affected Version(s)

dhis2-core >= 2.42.0, < 2.42.5.1 < 2.42.0, 2.42.5.1

dhis2-core >= 2.43.0, < 2.43.0.1 < 2.43.0, 2.43.0.1

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.