VYPR
High severityNVD Advisory· Published Sep 11, 2026

CVE-2026-44715

CVE-2026-44715

Description

OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the startHl7ArchiveMigration method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Openmrs/Openmrs Coreinferred2 versions
    <1.23.0, <2.10.0+ 1 more
    • (no CPE)range: <1.23.0, <2.10.0
    • (no CPE)range: <1.23.0, <2.10.0
  • Openmrs/Openmrsllm-fuzzy
    Range: <1.23.0, <2.10.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.