EIP-2026-119680

PRE-CVE

OpenMRS 2.3 (1.11.4) - Local File Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119680. PoCs published by LiquidWorm.

AI-analyzed exploit summary The exploit demonstrates a local file disclosure vulnerability in OpenMRS by leveraging a directory traversal attack via the 'url' parameter in the 'viewPortlet.htm' script. The provided URLs show how an attacker can access sensitive files like 'web.xml' and 'pom.xml' by traversing directories.

Description

OpenMRS 2.3 (1.11.4) - Local File Disclosure

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappsxml
https://www.exploit-db.com/exploits/38899

The exploit demonstrates a local file disclosure vulnerability in OpenMRS by leveraging a directory traversal attack via the 'url' parameter in the 'viewPortlet.htm' script. The provided URLs show how an attacker can access sensitive files like 'web.xml' and 'pom.xml' by traversing directories.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: OpenMRS 2.3, 2.2, 2.1, 2.0 (Platform 1.11.4, 1.11.2, 1.10.0) and OpenMRS-TB System (OpenMRS 1.9.7)
No auth needed
Prerequisites: Access to the OpenMRS web interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026