# CVE-2026-44715

## Summary

- **CVE ID:** CVE-2026-44715
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-285
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 15, 2026

## Description

OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.

## Affected Products

- openmrs — org.openmrs.module:legacyui-api (< 1.23.0)
- openmrs — org.openmrs.module:legacyui-api (>= 2.0.0, < 2.10.0)

## References

- [CNA](https://github.com/openmrs/openmrs-core/security/advisories/GHSA-g7rc-8fr4-5p2p)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.24%
- **EPSS Percentile:** 15.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._