CVE-2026-44715

Summary

OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the startHl7ArchiveMigration method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.

Affected Software

VendorProductVersion RangeStatus
openmrsorg.openmrs.module:legacyui-api< 1.23.0affected
openmrsorg.openmrs.module:legacyui-api>= 2.0.0, < 2.10.0affected

Weaknesses

  • CWE-285: CWE-285: Improper Authorization

References