Server-Side Request Forgery Vulnerability in Koha by Koha Community
CVE-2026-26379

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 June 2026

What is CVE-2026-26379?

Koha software versions up to 25.11 have a vulnerability that allows authenticated attackers to exploit a Server-Side Request Forgery (SSRF) due to improper Z39.50/SRU server configuration. This flaw enables attackers to potentially conduct internal network scans, thereby revealing sensitive information about internal services by analyzing the response times from the server. It is crucial for users of affected Koha versions to review their configurations and apply necessary security measures.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.