Sceawere
Vulnerability Detail
CVE-2026-55083UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DHIS2 Unsafe Java Deserialization RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 1d ago
- Vendor
- dhis2
- Product
- dhis2-core
- Attack Type
- CWE-502: Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-10-01T19:17:21.330Z",
"pubdate": "2026-10-01T19:17:21.330Z",
"executiveSummary": "DHIS2 is susceptible to a critical remote code execution (RCE) vulnerability stemming from improper handling of serialized Java objects. This security flaw allows an unauthenticated or authenticated attacker—depending on the specific entry point—to execute arbitrary code within the context of the application server. The vulnerability exists due to unsafe Java deserialization practices, which fail to validate or restrict the classes instantiated during the deserialization process. Successful exploitation results in complete system compromise, enabling attackers to gain unauthorized access to data, modify system configurations, or deploy persistent malware. Given the role of DHIS2 as a core information system for data management and analytics, the compromise of the underlying infrastructure poses significant risks to data integrity, confidentiality, and organizational operations. Affected versions include 2.42.0 through 2.42.5.0 and 2.43.0. The vulnerability has been remediated in versions 2.42.5.1, 2.43.0.1, and 2.44, necessitating immediate updates for all deployments within the impacted range.",
"technicalDetails": "The vulnerability is rooted in the insecure deserialization of objects provided by user-controlled input within the DHIS2 platform. In Java, the 'readObject()' method is used to deserialize data streams into objects. If the application does not implement strict look-ahead deserialization or utilize a restrictive 'ObjectInputStream' filter, an attacker can supply a malicious serialized object containing a 'gadget chain'—a sequence of method calls residing in the application's classpath that, when triggered during the deserialization process, lead to arbitrary code execution.\nThe attack flow typically initiates when an attacker sends a crafted serialized payload to an endpoint that processes incoming object streams. Because the application logic fails to validate the class type of the incoming serialized data, the JVM proceeds to reconstruct the malicious object graph. As the object is instantiated and fields are populated, the gadget chain is executed. Common gadget chains involve classes within the standard library or third-party dependencies (such as common Apache Commons Collections or other integrated libraries) that perform system-level operations, such as executing shell commands via 'java.lang.Runtime.exec()' or 'ProcessBuilder'.\nThis vulnerability is classified as critical because it bypasses standard application-level access controls. Once the exploit triggers the execution of arbitrary code, the attacker operates with the same privileges as the DHIS2 process on the host operating system. This allows for post-exploitation activities such as exfiltrating the database credentials from configuration files, pivoting within the internal network, or deploying secondary backdoors. The lack of validation on deserialized data effectively renders traditional boundary security ineffective if the exploit is delivered via permitted network protocols. Systems running versions 2.42.0 to 2.42.5.0 and 2.43.0 are explicitly vulnerable. The absence of object serialization filtering in these versions constitutes the primary failure point, allowing the reconstruction of dangerous objects that facilitate RCE.\nRemediation requires updating the platform to versions 2.42.5.1, 2.43.0.1, or 2.44, which include the necessary integrity checks and class filtering mechanisms to prevent the instantiation of malicious gadget chains. Administrators should also monitor server logs for anomalous deserialization patterns or unauthorized process execution originating from the DHIS2 service account."
}