Junglewise Threat Intelligence

CVE-2026-44715: OpenMRS broken access control in HL7 configuration

CVE-2026-44715 · Severity: info · Published 2026-09-11

Executive brief

OpenMRS is an open-source electronic medical records system used by healthcare organizations to store and manage patient data. An authenticated user with non-administrative privileges can exploit a broken access control vulnerability to trigger administrative HL7 archive migration functions they should not have permission to access, potentially allowing unauthorized modification of critical healthcare data.

Technical details

Broken access control vulnerability in the DWR (Direct Web Remoting) service layer allows authenticated users to call the startHl7ArchiveMigration administrative method without proper authorization checks. The vulnerability requires authentication but no elevated privileges, and is exploitable over the network. A successful exploit grants attackers the ability to execute administrative operations on HL7 configuration data.

Affected products

  • OpenMRS OpenMRS prior to 1.23.0 and 2.10.0
  • OpenMRS legacyui-api 1.23.0 and earlier, 2.0.0 through 2.9.x

Timeline

  • 2026-06-03: disclosed
  • 2026-09-11: advisory
  • 2026-06-03: patched: Versions 1.23.0 and 2.10.0 patch the issue

References