CVE-2026-55081: DHIS2 Reflected XSS in OpenAPI HTML scope parameter

Published Jul 21, 2026
·
Updated

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflected values from the scope query parameter into the generated HTML document without sufficient sanitization. A crafted scope value could be rendered as active HTML or JavaScript in the OpenAPI documentation page. An attacker able to get a user to open a crafted OpenAPI HTML URL could execute JavaScript in that user's browser in the DHIS2 origin.

Affected versions: DHIS2 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged. Patched in 2.42.5.1, 2.43.0.1, the 2.42 and 2.43 line branches, and the 2.44 development branch.

Affected Software

2 affected components
DHIS2 DHIS2>2.42<=2.42.5.1, >2.43<=2.43.0.1
DHIS2 DHIS2 2.44<2.44

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade DHIS2 to a version that resolves this vulnerability.

    Fixed in 2.42.5.1
  2. Upgrade

    Upgrade DHIS2 to a version that resolves this vulnerability.

    Fixed in 2.43.0.1
  3. Upgrade

    Upgrade DHIS2 to a version that resolves this vulnerability.

    Fixed in 2.44

Event History

Jul 21, 2026
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-55081?

CVE-2026-55081 has a risk score of 32, indicating a moderate severity level.

2

How do I fix CVE-2026-55081?

To fix CVE-2026-55081, ensure that the `scope` query parameter in the OpenAPI HTML endpoint is properly sanitized before being rendered.

3

What type of vulnerability is CVE-2026-55081?

CVE-2026-55081 is classified as a reflected cross-site scripting (XSS) vulnerability.

4

Which software is affected by CVE-2026-55081?

CVE-2026-55081 affects the DHIS2 application, specifically versions up to DHIS2 2.44.

5

What can an attacker do with CVE-2026-55081?

An attacker can exploit CVE-2026-55081 by injecting malicious content through the `scope` parameter, potentially compromising user data and session integrity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203