A vulnerability marked as critical has been reported in DHIS2 2.37/2.38/2.39. This vulnerability affects unknown code of the component SQL View. Performing a manipulation results in sql injection.

This vulnerability is identified as CVE-2026-55082. The attack can be initiated remotely. There is not any exploit available.