Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dhis2
Dhis2 dhis2-core |
|
| Vendors & Products |
Dhis2
Dhis2 dhis2-core |
Thu, 01 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44. | |
| Title | DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE) | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-01T18:30:36.526Z
Reserved: 2026-06-16T14:33:35.711Z
Link: CVE-2026-55083
Updated: 2026-10-01T18:30:33.411Z
Status : Received
Published: 2026-10-01T19:17:21.330
Modified: 2026-10-01T19:17:21.330
Link: CVE-2026-55083
No data.
OpenCVE Enrichment
Updated: 2026-10-01T19:30:11Z