SQL Injection Vulnerability in Koha Report Builder by Koha Community
CVE-2026-71288

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71288?

A vulnerability in Koha's guided report builder allows for SQL injection via unsanitized user input. The order_by parameter and its corresponding dynamically-named parameter are concatenated directly into an SQL ORDER BY clause without validation. This flaw gives low-privilege accounts the ability to execute time-based blind SQL injection attacks against the Koha database, potentially exposing sensitive patron information and staff credentials.

Affected Version(s)

Koha 0 <= 26.05.01-1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Saidakbarxon Maxsudxonov
.