SQL Injection Vulnerability in Koha's Reports Feature
CVE-2026-70371

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70371?

A vulnerability exists in the Koha reports module where unvalidated user input is concatenated directly into dynamic SQL queries. This flaw allows authenticated staff users with report module permissions to inject arbitrary SQL commands. As a result, attackers could potentially access sensitive data such as user credentials, two-factor authentication secrets, personal information, API keys, and session data by exploiting this SQL injection vulnerability. It is crucial for Koha users to be aware of this issue and implement necessary security measures to safeguard their databases and user information.

Affected Version(s)

Koha 0 <= 24.11.17

Koha 25.05.00 <= 25.05.12

Koha 25.11.00 <= 25.11.06

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.