PT-2026-36946 · Unknown · Openmrs-Api

Published

2026-05-04

·

Updated

2026-06-03

·

CVE-2026-41258

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openmrs-api versions prior to 2.7.9 openmrs-api versions prior to 2.8.6
Description Server-side template injection (SSTI) occurs via Velocity, which allows for remote code execution (RCE). SSTI is a flaw where an attacker can inject malicious code into a template, which is then executed on the server.
Recommendations Update to version 2.7.9. Update to version 2.8.6.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41258
GHSA-XJ4F-8JJG-VX4Q

Affected Products

Openmrs-Api