SQL Injection Vulnerability in Apache Fineract's Report Execution API
CVE-2026-35152
8.8HIGH
What is CVE-2026-35152?
A SQL Injection vulnerability has been identified in the Report Execution API of Apache Fineract, specifically within the runreports endpoint. This issue arises from inadequate validation of report parameter values incorporated into the SQL queries, enabling an authenticated userâwith the necessary permissions to run reportsâto inject arbitrary SQL commands. Exploiting this vulnerability can lead to unauthorized access to sensitive data that the report was not meant to reveal. Users are advised to upgrade to the latest version where this vulnerability has been addressed.
Affected Version(s)
Apache Fineract 0 <= 1.14.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
JD Security Shenyi Team
Geo Chen
Quac Tran
Terence Monteiro (@terencemo)
ĂdĂĄm SĂĄghy (@adamsaghy)
Aleksandar Vidakovic (@vidakovic)