CVE-2026-55083
9.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Summary
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dhis2 | dhis2-core | >= 2.42.0, < 2.42.5.1 | affected |
| dhis2 | dhis2-core | >= 2.43.0, < 2.43.0.1 | affected |
Weaknesses
- CWE-502: CWE-502: Deserialization of Untrusted Data
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/dhis2/dhis2-core/security/advisories/GHSA-3fr2-wvqx-cmr5
- https://github.com/dhis2/dhis2-core/releases/tag/2.42.5.1
- https://github.com/dhis2/dhis2-core/releases/tag/2.43.0.1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.