Junglewise Threat Intelligence

CVE-2026-55081: DHIS2 dhis2-core reflected XSS in OpenAPI HTML endpoint

CVE-2026-55081 · Severity: info · CVSS 7.3 · Published 2026-07-21

Technologies: DHIS2 Core. Vendors: DHIS2.

Executive brief

DHIS2 is an information system used for data management and analytics. A security vulnerability in its OpenAPI documentation component allows attackers to inject malicious scripts into the application. If a user clicks a specially crafted link, the attacker could execute actions on their behalf or access sensitive data within the DHIS2 platform.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the DHIS2 OpenAPI HTML endpoint. The root cause is the failure to sanitize the 'scope' query parameter before reflecting its value into the generated HTML document header and an inline 'onclick' JavaScript string. An attacker can exploit this by tricking an authenticated user into visiting a crafted URL, leading to the execution of arbitrary JavaScript in the context of the user's session. This could result in session hijacking or unauthorized actions within the DHIS2 origin. The issue is resolved by stripping HTML-significant characters from the scope key and value during parsing.

Affected products

  • dhis2 dhis2-core >= 2.42.0, < 2.42.5.1
  • dhis2 dhis2-core >= 2.43.0, < 2.43.0.1
  • dhis2 dhis2-core 2.44 development branch before 2026-06-09

Timeline

  • 2026-06-09: patched: Security patch releases and branch merges completed
  • 2026-07-21: advisory: NVD publication date

References

Related threats