SQL Injection Vulnerability in Koha Open Source ILS Software
CVE-2026-70372
Currently unrated
What is CVE-2026-70372?
The Koha integrated library system has a vulnerability that allows authenticated staff users, who have access to the reports module, to execute arbitrary SQL queries. This vulnerability arises from improper handling of user input in a SQL query construction process. Sensitive data, including password hashes, personal information, and API keys, can be exposed through this flaw. Specifically, the dynamic SQL is created by concatenating user-controlled parameters without appropriate validation, which can lead to a breach of user privacy and data integrity.
Affected Version(s)
Koha 0 < 24.11.17
Koha 25.05.00 < 25.05.12
Koha 25.11.00 < 25.11.06
