CVE-2026-44715: OpenMRS has Broken Access Control in HL7 Configuration
OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the startHl7ArchiveMigration method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenMRSto a version that resolves this vulnerability.Fixed in 1.23.0 - Upgrade
Upgrade
OpenMRSto a version that resolves this vulnerability.Fixed in 2.10.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated OpenMRS user can exploit the issue in affected versions; administrator-level privileges are not required.
What capability does exploitation provide?
An authenticated user can invoke the administrative DWR startHl7ArchiveMigration method, which initiates HL7 archive migration.
Which deployments are affected?
OpenMRS deployments running versions earlier than 1.23.0 or 2.10.0 are affected. Versions 1.23.0 and 2.10.0 include the fix.
What should teams do to remediate the issue?
Upgrade OpenMRS to version 1.23.0 or 2.10.0. The provided information does not identify an alternative mitigation for environments that cannot immediately upgrade.