SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-44715

HIGH · CVSS 8.7 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Authenticated users in OpenMRS versions prior to 1.23.0 and 2.10.0 can exploit unrestricted access to the `startHl7ArchiveMigration` method, which is intended for admin-level accounts, potentially allowing unauthorized administrative actions. This vulnerability poses a significant risk to the integrity and confidentiality of medical records managed by the platform. Organizations using affected versions should prioritize upgrading to the patched releases to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44715
Severity
HIGH
CVSS
8.7
EPSS
0.24%

Original NVD Description

OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.