Description
OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.
Published: 2026-09-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Administrative Access
Action: Apply Patch
AI Analysis

Impact

OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, any authenticated user could invoke the startHl7ArchiveMigration method, which should be restricted to administrator accounts. This access control flaw allows a non‑admin authenticated user to trigger administrative DWR services. The vulnerability is rooted in improper privilege management (CWE‑285).

Affected Systems

The vulnerability affects the OpenMRS legacyui-api module in releases prior to version 1.23.0 in the 1.x line and prior to version 2.10.0 in the 2.x line. Subsequent releases, 1.23.0 and 2.10.0, contain the patch that removes the flaw.

Risk and Exploitability

The CVSS base score of 8.7 indicates high severity. An EPSS score of < 1% and the absence of a CISA KEV listing suggest a low probability of exploitation in the wild. Because the method requires authentication, the attacker must already be authenticated to OpenMRS; the likely attack vector is authenticated application‑level access. This access control weakness permits any authenticated user to invoke the startHl7ArchiveMigration method, which should be reserved for administrators. Based on the description, it is inferred that the method may alter HL7 configuration, and this inferred Applying the vendor‑supplied fix mitigates the risk.

Generated by OpenCVE AI on September 15, 2026 at 20:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to OpenMRS 1.23.0, 2.10.0, or any later release that contains the fix
  • Enforce role‑based access control to ensure that the startHl7ArchiveMigration method can be called only by administrator accounts
  • If an immediate upgrade is not feasible, temporarily disable or block the DWR endpoint via application configuration or a network firewall

Generated by OpenCVE AI on September 15, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Openmrs
Openmrs org.openmrs.module:legacyui-api
Vendors & Products Openmrs
Openmrs org.openmrs.module:legacyui-api

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.
Title OpenMRS has Broken Access Control in HL7 Configuration
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openmrs Org.openmrs.module:legacyui-api
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T16:42:38.624Z

Reserved: 2026-05-07T17:07:09.319Z

Link: CVE-2026-44715

cve-icon Vulnrichment

Updated: 2026-09-15T16:42:31.687Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T22:16:37.113

Modified: 2026-09-25T14:23:59.847

Link: CVE-2026-44715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:45:20Z

Weaknesses