CVE-2026-55081: DHIS2 Reflected XSS in OpenAPI HTML scope parameter
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflected values from the scope query parameter into the generated HTML document without sufficient sanitization. A crafted scope value could be rendered as active HTML or JavaScript in the OpenAPI documentation page. An attacker able to get a user to open a crafted OpenAPI HTML URL could execute JavaScript in that user's browser in the DHIS2 origin.
Affected versions: DHIS2 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged. Patched in 2.42.5.1, 2.43.0.1, the 2.42 and 2.43 line branches, and the 2.44 development branch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DHIS2to a version that resolves this vulnerability.Fixed in 2.42.5.1 - Upgrade
Upgrade
DHIS2to a version that resolves this vulnerability.Fixed in 2.43.0.1 - Upgrade
Upgrade
DHIS2to a version that resolves this vulnerability.Fixed in 2.44
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55081?
CVE-2026-55081 has a risk score of 32, indicating a moderate severity level.
How do I fix CVE-2026-55081?
To fix CVE-2026-55081, ensure that the `scope` query parameter in the OpenAPI HTML endpoint is properly sanitized before being rendered.
What type of vulnerability is CVE-2026-55081?
CVE-2026-55081 is classified as a reflected cross-site scripting (XSS) vulnerability.
Which software is affected by CVE-2026-55081?
CVE-2026-55081 affects the DHIS2 application, specifically versions up to DHIS2 2.44.
What can an attacker do with CVE-2026-55081?
An attacker can exploit CVE-2026-55081 by injecting malicious content through the `scope` parameter, potentially compromising user data and session integrity.