CVE-2026-55082: DHIS2 SQL injection in SQL View filter values

Published Jul 21, 2026
·
Updated

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL View data endpoints allowed authenticated users with SQL View access to provide crafted filter values that were interpolated into generated SQL. An authenticated user with access to SQL View execution could manipulate SQL generated for SQL View filters and potentially access data outside the intended SQL View result set.

This is distinct from CVE-2026-55084, which tracks the related SQL View filter column-name injection.

Known affected release lines for this advisory: DHIS2 2.37, 2.38, and 2.39 before the 2026-06-09 EOS security updates. Patched by the 2026-06-09 EOS security updates for 2.37, 2.38, and 2.39. The same value-slot hardening was already present on later supported branches through DHIS2-20174 / PR #22253.

Affected Software

1 affected component
DHIS2 DHIS2>2.37<=2.39, <2026-06-09

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade DHIS2 to a version that resolves this vulnerability.

    Fixed in 2.37Patch 2026-06-09 EOS security updates
  2. Upgrade

    Upgrade DHIS2 to a version that resolves this vulnerability.

    Fixed in 2.38Patch 2026-06-09 EOS security updates
  3. Upgrade

    Upgrade DHIS2 to a version that resolves this vulnerability.

    Fixed in 2.39Patch 2026-06-09 EOS security updates
  4. Compensating control

    Apply the value-slot hardening referenced by DHIS2-20174 / PR #22253 to ensure crafted SQL View filter values are not interpolated into generated SQL in a way that allows SQL injection or data access outside the intended SQL View result set.

Event History

Jul 21, 2026
CVE Published
via MITRE·06:43 PM
Data Sourced
via MITRE·06:43 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-55082?

CVE-2026-55082 has a risk rating of 44, indicating a medium level of severity.

2

How do I fix CVE-2026-55082?

To fix CVE-2026-55082, ensure that proper input validation and prepared statements are implemented in SQL Views to prevent SQL injection.

3

What software is affected by CVE-2026-55082?

CVE-2026-55082 affects DHIS2 software, specifically its SQL View data endpoints.

4

Who is vulnerable to CVE-2026-55082?

Authenticated users with SQL View access to the DHIS2 system are vulnerable to CVE-2026-55082.

5

What types of attacks does CVE-2026-55082 allow?

CVE-2026-55082 allows for SQL injection attacks if crafted filter values are provided by authenticated users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203