SQL Injection Vulnerability in Koha Library Management Software
CVE-2026-70369

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70369?

In Koha's reports/acquisitions_stats.pl, the application builds SQL queries using user-controlled parameters without proper sanitization or prepared statements. This vulnerability allows authenticated users with reports module permission to execute arbitrary SQL queries. As a result, attackers can potentially read sensitive information from various database tables, including personal data, password hashes, and API keys, posing a significant risk to the confidentiality and integrity of the data managed by Koha.

Affected Version(s)

Koha 0 <= 24.11.17

Koha 25.05.00 <= 25.05.12

Koha 25.11.00 <= 25.11.06

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.