CVE-2026-40076Disclousure(openmrs / openmrs)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module upload endpoint at POST `/openmrs/ws/rest/v1/module` is vulnerable to a Zip Slip path traversal attack. During automatic extraction of uploaded .omod archives in `WebModuleUtil.startModule()`, ZIP entries under web/module/ are checked only to see whether the full entry path starts with `..,` and the remaining path is then concatenated into the destination path without normalization or a boundary check. A crafted archive can therefore include entries such as `web/module/../../../../malicious.jsp` and cause files to be written outside the intended module directory. An authenticated attacker with module upload access can write arbitrary files to locations such as the web application root and achieve remote code execution by uploading a JSP file and then requesting it. The issue is compounded by the fact that the module.allow_web_admin runtime property is enforced in the legacy UI controller but not in the REST API upload path, so deployments relying on that property to block web-based module administration remain exposed through the REST endpoint. This issue has been fixed in versions after 2.7.8 in the 2.7.x line and in version 2.8.6 and later.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openmrs

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclousure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
openmrs

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-07: 2Technical Details · 2026-05-07: 105-07
Signal classification2 categories
Disclousure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-40076 OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module upload endpoint a… https://www.cve.org/CVERecord?id=CVE-2026-40076

    Post summary

    The text briefly records CVE-2026-40076 for OpenMRS Core with version range details and a link to the CVE entry, but offers no further technical depth, exploits, or mitigation information.

    0001097
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclousure

    CVE-2026-40076 Zip Slip Path Traversal in OpenMRS Core Module Upload Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40076

    Post summary

    A path traversal vulnerability (Zip Slip) affecting the OpenMRS Core Module Upload Endpoint has been disclosed under CVE‑2026‑40076.

    0000046
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenmrsopenmrs---

Explore more