SQL Injection Vulnerability in Koha's Circulation Statistics Report
CVE-2026-70373

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70373?

In Koha's circulation statistics report, user-controlled input parameters are directly concatenated into an SQL string without proper sanitization. This oversight allows authenticated users with permission to the reports module to inject arbitrary SQL queries. As a result, attackers can access sensitive information from any table within the Koha database, including borrowers' personal data, passwords, and API keys. This vulnerability highlights the critical need for secure coding practices to prevent unauthorized data exposure in library management systems.

Affected Version(s)

Koha 0 <= 24.11.17

Koha 25.05.00 <= 25.05.12

Koha 25.11.00 <= 25.11.06

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.