Critical OpenMRS Flaws Enable Patient Data Theft and Remote Server Takeover
ID: 19413df7-cf3b-5a03-aef0-e87f504c4722
STIX ID: report--19413df7-cf3b-5a03-aef0-e87f504c4722
Feed Name: securityonline.info
Threat Score
OpenMRS issued urgent security updates for three critical vulnerabilities — notably CVE-2026-41258 (SSTI, CVSS 9.1) that allows users with the Manage Concepts privilege to execute arbitrary commands and exfiltrate PHI, plus a Zip Slip RCE via module uploads and an unauthenticated file-read path traversal — and urges immediate upgrade to 2.8.6/2.7.9 or application of mitigations to protect patient data and system integrity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
