Junglewise Threat Intelligence

CVE-2026-55082: DHIS2 SQL injection in SQL View data endpoints

CVE-2026-55082 · Severity: info · CVSS 8.7 · Published 2026-07-21

Technologies: DHIS2 Core. Vendors: DHIS2.

Executive brief

DHIS2 is an open-source health information management system used globally for data collection and analysis. A security flaw in the SQL View component allowed authorized users to run unauthorized database commands by providing specially crafted filter values. This could lead to the exposure of sensitive health data, unauthorized modification of records, or disruption of the system's database operations.

Technical details

A SQL injection vulnerability exists in the DHIS2 SQL View data endpoints due to improper neutralization of special elements in filter values. Authenticated users with SQL View execution privileges could provide crafted input that is directly interpolated into generated SQL queries rather than being handled via parameter binding. This allows for arbitrary SQL execution, potentially enabling access to data outside the intended result set or full database compromise. The vulnerability was addressed by implementing JDBC parameter binding for criteria and filter parameters and identifier quoting for field inputs. This issue is tracked separately from CVE-2026-55084, which involves column-name injection in the same component.

Affected products

  • DHIS2 DHIS2 Core 2.37, 2.38, and 2.39 before 2026-06-09 security updates

Timeline

  • 2025-10-16: other: Initial fix merged into master branch
  • 2026-06-09: patched: Security updates released for legacy versions 2.37, 2.38, and 2.39
  • 2026-07-21: disclosed: CVE published to NVD

References

Related threats