๐Ÿ” CVE Alert

CVE-2026-55084

HIGH 8.8

SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the `/api/sqlViews/{viewId}/data.json` endpoint. An authenticated user with access to a SqlView can inject arbitrary SQL queries inside the `filter` parameter by abusing an expression executed by PostgreSQL and its output is reflected inside the application error message. This behavior enables attackers to extract arbitrary database content using error-based SQL injection. Affected versions include: 2.37, 2.38, 2.39, 2.40.x before 2.40.11.1/2.40.12, 2.41.x before 2.41.8.2, 2.42.x before 2.42.5.1, 2.43.0 before 2.43.0.1, 2.44 development branch before PR #24162 Patched versions include: 2.37-EOS (2026-06-09), 2.38-EOS (2026-06-09), 2.39-EOS (2026-06-09), 2.40.11.1, 2.40.12, 2.41.8.2, 2.42.5.1, 2.43.0.1, 2.44 development branch after PR #24162

CWE CWE-89
Vendor dhis2
Product dhis2-core
Published Jul 21, 2026
Last Updated Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for dhis2 dhis2-core

Be the first to know when new high vulnerabilities affecting dhis2 dhis2-core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

dhis2 / dhis2-core
>= 2.37, <= 2.39 >= 2.40.0, < 2.40.11.1 >= 2.41.0, < 2.41.8.2 >= 2.42.0, < 2.42.5.1 >= 2.43.0, < 2.43.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dhis2/dhis2-core/security/advisories/GHSA-pwmg-mvjw-4m23 github.com: https://github.com/dhis2/dhis2-core/pull/24162