CVE-2026-55082: DHIS2 SQL injection in SQL View filter values
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL View data endpoints allowed authenticated users with SQL View access to provide crafted filter values that were interpolated into generated SQL. An authenticated user with access to SQL View execution could manipulate SQL generated for SQL View filters and potentially access data outside the intended SQL View result set.
This is distinct from CVE-2026-55084, which tracks the related SQL View filter column-name injection.
Known affected release lines for this advisory: DHIS2 2.37, 2.38, and 2.39 before the 2026-06-09 EOS security updates. Patched by the 2026-06-09 EOS security updates for 2.37, 2.38, and 2.39. The same value-slot hardening was already present on later supported branches through DHIS2-20174 / PR #22253.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DHIS2to a version that resolves this vulnerability.Fixed in 2.37Patch 2026-06-09 EOS security updates - Upgrade
Upgrade
DHIS2to a version that resolves this vulnerability.Fixed in 2.38Patch 2026-06-09 EOS security updates - Upgrade
Upgrade
DHIS2to a version that resolves this vulnerability.Fixed in 2.39Patch 2026-06-09 EOS security updates - Compensating control
Apply the value-slot hardening referenced by DHIS2-20174 / PR #22253 to ensure crafted SQL View filter values are not interpolated into generated SQL in a way that allows SQL injection or data access outside the intended SQL View result set.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55082?
CVE-2026-55082 has a risk rating of 44, indicating a medium level of severity.
How do I fix CVE-2026-55082?
To fix CVE-2026-55082, ensure that proper input validation and prepared statements are implemented in SQL Views to prevent SQL injection.
What software is affected by CVE-2026-55082?
CVE-2026-55082 affects DHIS2 software, specifically its SQL View data endpoints.
Who is vulnerable to CVE-2026-55082?
Authenticated users with SQL View access to the DHIS2 system are vulnerable to CVE-2026-55082.
What types of attacks does CVE-2026-55082 allow?
CVE-2026-55082 allows for SQL injection attacks if crafted filter values are provided by authenticated users.