Bahmni · Bahmnicore · CVE-2026-15477
**Name of the Vulnerable Software and Affected Versions**
Bahmni bahmnicore versions prior to 0.93.1
**Description**
An issue exists in the Search Endpoint component where the `additionalParams` function within the '/openmrs/ws/rest/v1/bahmnicore/sql' endpoint is susceptible to SQL injection. This occurs when the `test` argument is manipulated, allowing a remote attacker to execute unauthorized SQL commands.
**Recommendations**
Upgrade to version 0.93.1, 1.0.1, 1.1.1, 1.2.1, 1.3.1, or 2.0.1.
As a temporary mitigation, restrict access to the '/openmrs/ws/rest/v1/bahmnicore/sql' endpoint or avoid using the `test` argument.