Executive brief
Bahmni, an open-source hospital information system, is affected by a security flaw in its core search component. An authorized user could exploit this vulnerability to bypass security controls and extract sensitive patient information from the hospital's database. This could lead to a significant breach of patient privacy and regulatory non-compliance.
Technical details
A SQL injection vulnerability exists in the Bahmni bahmnicore module (specifically bahmnicore-omod) within the 'additionalParams' function of the Search Endpoint (/openmrs/ws/rest/v1/bahmnicore/sql). The flaw is triggered by manipulating the 'test' argument, allowing for boolean-blind and error-based exfiltration techniques. While the endpoint is intended for search, improper neutralization of SQL commands allows an authenticated attacker with network access to read sensitive data from the underlying database. The issue affects versions 0.93 and above, and has been patched in versions 0.93.1, 1.0.1, 1.1.1, 1.2.1, 1.3.1, and 2.0.1.
Affected products
- Bahmni bahmnicore-omod 0.93 and above
Timeline
- 2026-07-02: advisory: Vendor security patch and release notes published
- 2026-07-12: disclosed: CVE published to NVD dataset
References
- https://bahmni.atlassian.net/wiki/spaces/BAH/pages/5519474693/Bahmni+Security+Patch+July+02+2026+Release+Notes
- https://github.com/Bahmni/bahmni-core/security/advisories/GHSA-cg9w-r5g6-cxq5
- https://vuldb.com/cve/CVE-2026-15477
- https://vuldb.com/submit/836079
- https://vuldb.com/vuln/377782
- https://vuldb.com/vuln/377782/cti