SQL Injection Vulnerability in Koha Library Management Software
CVE-2026-70369
Currently unrated
What is CVE-2026-70369?
In Koha's reports/acquisitions_stats.pl, the application builds SQL queries using user-controlled parameters without proper sanitization or prepared statements. This vulnerability allows authenticated users with reports module permission to execute arbitrary SQL queries. As a result, attackers can potentially read sensitive information from various database tables, including personal data, password hashes, and API keys, posing a significant risk to the confidentiality and integrity of the data managed by Koha.
Affected Version(s)
Koha 0 < 24.11.17
Koha 25.05.00 < 25.05.12
Koha 25.11.00 < 25.11.06
