Sceawere

Vulnerability Detail

CVE-2026-55083UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DHIS2 Unsafe Java Deserialization RCE

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
dhis2
Product
dhis2-core
Attack Type
CWE-502: Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-10-01T19:17:21.330Z",
  "pubdate": "2026-10-01T19:17:21.330Z",
  "executiveSummary": "DHIS2 is susceptible to a critical remote code execution (RCE) vulnerability stemming from improper handling of serialized Java objects. This security flaw allows an unauthenticated or authenticated attacker—depending on the specific entry point—to execute arbitrary code within the context of the application server. The vulnerability exists due to unsafe Java deserialization practices, which fail to validate or restrict the classes instantiated during the deserialization process. Successful exploitation results in complete system compromise, enabling attackers to gain unauthorized access to data, modify system configurations, or deploy persistent malware. Given the role of DHIS2 as a core information system for data management and analytics, the compromise of the underlying infrastructure poses significant risks to data integrity, confidentiality, and organizational operations. Affected versions include 2.42.0 through 2.42.5.0 and 2.43.0. The vulnerability has been remediated in versions 2.42.5.1, 2.43.0.1, and 2.44, necessitating immediate updates for all deployments within the impacted range.",
  "technicalDetails": "The vulnerability is rooted in the insecure deserialization of objects provided by user-controlled input within the DHIS2 platform. In Java, the 'readObject()' method is used to deserialize data streams into objects. If the application does not implement strict look-ahead deserialization or utilize a restrictive 'ObjectInputStream' filter, an attacker can supply a malicious serialized object containing a 'gadget chain'—a sequence of method calls residing in the application's classpath that, when triggered during the deserialization process, lead to arbitrary code execution.\nThe attack flow typically initiates when an attacker sends a crafted serialized payload to an endpoint that processes incoming object streams. Because the application logic fails to validate the class type of the incoming serialized data, the JVM proceeds to reconstruct the malicious object graph. As the object is instantiated and fields are populated, the gadget chain is executed. Common gadget chains involve classes within the standard library or third-party dependencies (such as common Apache Commons Collections or other integrated libraries) that perform system-level operations, such as executing shell commands via 'java.lang.Runtime.exec()' or 'ProcessBuilder'.\nThis vulnerability is classified as critical because it bypasses standard application-level access controls. Once the exploit triggers the execution of arbitrary code, the attacker operates with the same privileges as the DHIS2 process on the host operating system. This allows for post-exploitation activities such as exfiltrating the database credentials from configuration files, pivoting within the internal network, or deploying secondary backdoors. The lack of validation on deserialized data effectively renders traditional boundary security ineffective if the exploit is delivered via permitted network protocols. Systems running versions 2.42.0 to 2.42.5.0 and 2.43.0 are explicitly vulnerable. The absence of object serialization filtering in these versions constitutes the primary failure point, allowing the reconstruction of dangerous objects that facilitate RCE.\nRemediation requires updating the platform to versions 2.42.5.1, 2.43.0.1, or 2.44, which include the necessary integrity checks and class filtering mechanisms to prevent the instantiation of malicious gadget chains. Administrators should also monitor server logs for anomalous deserialization patterns or unauthorized process execution originating from the DHIS2 service account."
}
CVE-2026-55083: DHIS2 Unsafe Java Deserialization RCE (CRITICAL Severity, CVSS: 9.1) | Sceawere