SQL Injection Vulnerability in Koha Open Source ILS Software
CVE-2026-70372

Currently unrated

Key Information:

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70372?

The Koha integrated library system has a vulnerability that allows authenticated staff users, who have access to the reports module, to execute arbitrary SQL queries. This vulnerability arises from improper handling of user input in a SQL query construction process. Sensitive data, including password hashes, personal information, and API keys, can be exposed through this flaw. Specifically, the dynamic SQL is created by concatenating user-controlled parameters without appropriate validation, which can lead to a breach of user privacy and data integrity.

Affected Version(s)

Koha 0 < 24.11.17

Koha 25.05.00 < 25.05.12

Koha 25.11.00 < 25.11.06

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.