CVE-2026-41258Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateCriteria() method in OpenMRS Core evaluates database-stored criteria strings as Apache Velocity templates without any sandbox configuration. The VelocityEngine is initialized with only logging properties and noSecureUberspector, leaving the default UberspectImpl in place, which allows unrestricted Java reflection through template expressions. A user with the Manage Concepts privilege can store a malicious Velocity template expression in a concept's reference range criteria field. This payload is then executed automatically whenever a user or API call validates an observation against the affected concept. The Velocity context exposes $patient (the Person / Patient object), $obs (the Obs object), and $fn (the ConceptReferenceRangeUtility instance with access to the full OpenMRS service layer). This vulnerability is fixed in 2.7.9 and 2.8.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-06-03)
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-05-04: 2Mentions · 2026-05-13: 1Mentions · 2026-06-03: 3Patch / Workaround · 2026-05-04: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-13: 1Technical Details · 2026-06-03: 205-0405-1306-03
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure2
2026-05-131
Patch1
2026-06-033
Disclosure2General1
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    General

    Sources GitHub Advisory GHSA-xj4f-8jjg-vx4q DailyCVE: OpenMRS Core CVE-2026-41258 MachineSpiritsBlog Advisory The Template That Never Should Trust: How OpenMRS Became a Persistent Backdoor for Healthcare Systems

    Post summary

    The post lists advisory sources and a blog title concerning a backdoor flaw in OpenMRS, but does not furnish explicit exploit details, mitigations, or technical specifications.

    1000028
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    A critical stored Velocity SSTI vulnerability (CVE-2026-41258, CVSS 9.1) in OpenMRS Core allows non-admin staff with "Manage Concepts" privileges to inject malicious template expressions into the database. Once stored, the payload persists and executes automatically on…

    Post summary

    The statement discloses a critical stored Velocity SSTI vulnerability (CVE‑2026‑41258) in OpenMRS Core, detailing its severity (CVSS 9.1), affected privileges, vector, and persistence.

    1000021
    239 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Template That Never Should Trust: CVE-2026-41258 Turns OpenMRS Into a Persistent Backdoor for Healthcare Systems. A critical stored Velocity SSTI vulnerability CVE-2026-41258, CVSS 9.1 in OpenMRS Core allows non-admin staff with "Manage Concepts" privileges to inject…

    Post summary

    This post announces a high‑severity Velocity SSTI vulnerability in OpenMRS (CVE‑2026‑41258) that could allow non‑admin users with Manage Concepts privileges to create persistent backdoors in healthcare systems.

    1000034
    239 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OpenMRS Core, Velocity SSTI to RCE, #CVE-2026-41258 (Critical) https://dailycve.com/openmrs-core-velocity-ssti-to-rce-cve-2026-41258-critical/

    Post summary

    The post announces a critical vulnerability (CVE‑2026‑41258) in OpenMRS Core that enables a Velocity Server‑Side Template Injection leading to Remote Code Execution, with a link to a detailed disclosure article.

    0001061
    191 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - OpenMRS SSTI to RCE (CVE-2026-41258) 
 org.openmrs.api:openmrs-api allows server-side template injection via Velocity, enabling remote code execution. 
 👉 Update to 2.7.9 / 2.8.6 immediately

    Post summary

    The tweet announces a critical SSTI vulnerability in OpenMRS (CVE‑2026‑41258) that enables RCE and urges immediate update to patched releases.

    0001081
    122 followersView on X
  • IntegSec@integ_sec
    Patch

    CVE-2026-41258: OpenMRS Server-Side Template Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04gpjGQ0

    Post summary

    The content references the CVE-2026-41258 OpenMRS Server‑Side Template Injection and seems to be an advisory outlining business impact and response guidance, but does not provide PoC, exploitation details, or patch specifics.

    0000028
    30 followersView on X

Explore more