CVE-2026-40075Disclosure(openmrs / openmrs)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnerable to a path traversal attack. The ModuleResourcesServlet constructs a filesystem path from user-controlled input without performing path boundary validation — the getFile() method concatenates the user-supplied path into an absolute filesystem path without calling normalize() or checking that the result stays within the allowed module resources directory. Because this endpoint serves static resources required for rendering the login page, it is not protected by authentication filters, allowing unauthenticated exploitation. An attacker can traverse directories and read arbitrary files from the server filesystem, including /etc/passwd and application configuration files containing database credentials. Successful exploitation requires the target deployment to run on Apache Tomcat versions prior to 8.5.31, where the ..; path parameter bypass is not mitigated by the container. Deployments on Tomcat 8.5.31 or later and Tomcat 9.0.10 or later are protected at the container level, though the underlying code defect remains. This issue has been fixed in versions after 2.7.8 (within the 2.7.x branch) and in version 2.8.6 and later.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openmrs

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openmrs

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 105-0505-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure1General1
2026-05-061
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40075 Path Traversal in OpenMRS Core 2.7.8 and 2.8.0-2.8.5 Unauthenticated Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40075

    Post summary

    The post announces CVE-2026‑40075, a path traversal vulnerability in OpenMRS Core 2.7.8 and 2.8.0‑2.8.5 that permits unauthenticated access, with no PoC, exploit, or patch cited.

    0000044
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40075 OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResource… https://www.cve.org/CVERecord?id=CVE-2026-40075 ----- Traducción: CVE-2026-40075 Ope… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-40075 affecting certain OpenMRS Core versions and links to the CVE record and a translation resource, but offers no detailed vulnerability analysis, patch information, or exploitation evidence.

    0000041
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40075 OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResource… https://www.cve.org/CVERecord?id=CVE-2026-40075

    Post summary

    The note confirms CVE-2026-40075 is relevant to older OpenMRS Core releases and pinpoints a vulnerable module path, but it provides no evidence of active exploitation, patches, or exploit code. Further detail is required to assess actual risk.

    00000248
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenmrsopenmrs---

Explore more