SQL Injection Vulnerability in Koha Open Source ILS Software
CVE-2026-70372

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70372?

The Koha integrated library system has a vulnerability that allows authenticated staff users, who have access to the reports module, to execute arbitrary SQL queries. This vulnerability arises from improper handling of user input in a SQL query construction process. Sensitive data, including password hashes, personal information, and API keys, can be exposed through this flaw. Specifically, the dynamic SQL is created by concatenating user-controlled parameters without appropriate validation, which can lead to a breach of user privacy and data integrity.

Affected Version(s)

Koha 0 <= 24.11.17

Koha 25.05.00 <= 25.05.12

Koha 25.11.00 <= 25.11.06

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.