Path traversal in OpenMRS - CVE-2026-40075
Published: May 4, 2026
OpenMRS
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in ModuleResourcesServlet when handling requests to the /openmrs/moduleResources/{moduleid} endpoint. A remote attacker can send a specially crafted request to disclose sensitive information.
Successful exploitation requires the target deployment to run on Apache Tomcat versions earlier than 8.5.31.