CVE-2026-55083: DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE)
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DHIS2to a version that resolves this vulnerability.Fixed in 2.42.5.1 - Upgrade
Upgrade
DHIS2to a version that resolves this vulnerability.Fixed in 2.43.0.1 - Upgrade
Upgrade
DHIS2to a version that resolves this vulnerability.Fixed in 2.44
Event History
Frequently Asked Questions
Which DHIS2 deployments are affected?
Affected versions are 2.42.0 through versions before 2.42.5.1, and 2.43.0 through versions before 2.43.0.1. The issue is fixed in 2.42.5.1, 2.43.0.1, and 2.44.
What level of access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable over the network with low attack complexity and requires high privileges. It does not require user interaction.
What is the potential impact if exploited?
Successful exploitation can result in remote code execution and has high impact on confidentiality, integrity, and availability. The scope may extend beyond the vulnerable component.