SQL Injection Vulnerability in Koha Library Management Software
CVE-2026-70369

Currently unrated

Key Information:

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70369?

In Koha's reports/acquisitions_stats.pl, the application builds SQL queries using user-controlled parameters without proper sanitization or prepared statements. This vulnerability allows authenticated users with reports module permission to execute arbitrary SQL queries. As a result, attackers can potentially read sensitive information from various database tables, including personal data, password hashes, and API keys, posing a significant risk to the confidentiality and integrity of the data managed by Koha.

Affected Version(s)

Koha 0 < 24.11.17

Koha 25.05.00 < 25.05.12

Koha 25.11.00 < 25.11.06

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.