OpenAPI HTML Endpoint Vulnerability in DHIS2 by DHIS2
CVE-2026-55081
What is CVE-2026-55081?
The DHIS2 information system is susceptible to a Cross-Site Scripting vulnerability through its OpenAPI HTML endpoint. This issue arises when the scope query parameter is reflected in the generated HTML without adequate sanitization. An attacker can exploit this flaw by crafting a malicious URL that, when accessed by an unsuspecting user, executes JavaScript code in their browser within the DHIS2 environment. This could lead to unauthorized actions or data exposure. The vulnerability affects DHIS2 versions 2.42 and 2.43 prior to the security patch on June 9, 2026. Users are encouraged to upgrade to patched versions 2.42.5.1, 2.43.0.1, or later to mitigate this risk.
Affected Version(s)
dhis2-core >= 2.42.0, < 2.42.5.1 < 2.42.0, 2.42.5.1
dhis2-core >= 2.43.0, < 2.43.0.1 < 2.43.0, 2.43.0.1
