---
id: CVE-2026-15477
title: A vulnerability was detected in Bahmni bahmnicore up to 0.93
summary: >-
  A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the
  function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of
  the component Search Endpoint. Performing a manipulation of the argument test
  resu…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
published: '2026-07-12'
updated: '2026-07-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15477'
references:
  - url: >-
      https://bahmni.atlassian.net/wiki/spaces/BAH/pages/5519474693/Bahmni+Security+Patch+July+02+2026+Release+Notes
    label: cna@vuldb.com
  - url: >-
      https://github.com/Bahmni/bahmni-core/security/advisories/GHSA-cg9w-r5g6-cxq5
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-15477'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/836079'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377782'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377782/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-07-12T05:18:58.873Z'
epss: 0.00333
epssPercentile: 0.23866
---

## Overview

A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. Performing a manipulation of the argument test results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 0.93.1, 1.0.1, 1.1.1, 1.2.1, 1.3.1 and 2.0.1 mitigates this issue. Upgrading the affected component is recommended.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
