SQL Injection Vulnerability in Koha's Reports Feature
CVE-2026-70371
Currently unrated
What is CVE-2026-70371?
A vulnerability exists in the Koha reports module where unvalidated user input is concatenated directly into dynamic SQL queries. This flaw allows authenticated staff users with report module permissions to inject arbitrary SQL commands. As a result, attackers could potentially access sensitive data such as user credentials, two-factor authentication secrets, personal information, API keys, and session data by exploiting this SQL injection vulnerability. It is crucial for Koha users to be aware of this issue and implement necessary security measures to safeguard their databases and user information.
Affected Version(s)
Koha 0 < 24.11.17
Koha 25.05.00 < 25.05.12
Koha 25.11.00 < 25.11.06
