CVE-2026-40075
openmrs openmrs-core, openmrs
OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnerable to a path traversal attack. The ModuleResourcesServlet constructs a filesystem path from user-controlled input without performing path boundary validation — the getFile() method concatenates the user-supplied path into an absolute filesystem path without calling normalize() or checking that the result stays within the allowed module resources directory. Because this endpoint serves static re...
- CVSS
- 8.2
- EPSS
- 0.56% 43.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.06