CVE-2026-44715
OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.
- Published Sep 11, 2026
- CVSS 8.7 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available