CVE-2026-15477 Details
Description
A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. Performing a manipulation of the argument test results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 0.93.1, 1.0.1, 1.1.1, 1.2.1, 1.3.1 and 2.0.1 mitigates this issue. Upgrading the affected component is recommended.
A SQL injection vulnerability has been identified in Bahmni Bahmnicore versions prior to 0.93. The issue resides in the Search Endpoint, specifically within the additionalParams function of the /openmrs/ws/rest/v1/bahmnicore/sql file. The vulnerability allows remote attackers to manipulate the 'test' argument, leading to SQL injection. This exploitation could be used to exfiltrate patient data from the database, although the vulnerability is now public and may be actively exploited.
Users are advised to upgrade to Bahmni Bahmnicore versions 0.93.1, 1.0.1, 1.1.1, 1.2.1, 1.3.1, or 2.0.1. If a specific implementation does not use the 'High Risk Patients' search query, the global property 'emrapi.sqlSearch.highRiskPatients' can be removed. For deployments targeting specific users within a certain network, access should be restricted to trusted IP addresses. Additionally, access to the SQL Search should be audited and monitored for unusual activity.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 12, 2026CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/836079 | CISA-ADP | Permission Required |
| https://bahmni.atlassian.net/wiki/spaces/BAH/pages/5519474693/Bahmni+Security+Patch+July+02+2026+Release+Notes | [email protected] | Release NotesVendor |
| https://github.com/Bahmni/bahmni-core/security/advisories/GHSA-cg9w-r5g6-cxq5 | [email protected] | AdvisoryRemedyVendor |
| https://vuldb.com/cve/CVE-2026-15477 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/836079 | [email protected] | Permission Required |
| https://vuldb.com/vuln/377782 | [email protected] | Permission Required |
| https://vuldb.com/vuln/377782/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Bahmni bahmnicore | >= 0.93 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 12, 2026 | New CVE Received | [email protected] |
Volerion