๐Ÿ” CVE Alert

CVE-2026-44715

UNKNOWN 0.0

OpenMRS has Broken Access Control in HL7 Configuration

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.

CWE CWE-285
Vendor openmrs
Product org.openmrs.module:legacyui-api
Published Sep 11, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for openmrs org.openmrs.module:legacyui-api

Be the first to know when new unknown vulnerabilities affecting openmrs org.openmrs.module:legacyui-api are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openmrs / org.openmrs.module:legacyui-api
< 1.23.0 >= 2.0.0, < 2.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openmrs/openmrs-core/security/advisories/GHSA-g7rc-8fr4-5p2p