SQL Injection Vulnerability in Koha Report Builder by Koha Community
CVE-2026-71288
8.8HIGH
What is CVE-2026-71288?
A vulnerability in Koha's guided report builder allows for SQL injection via unsanitized user input. The order_by parameter and its corresponding dynamically-named parameter are concatenated directly into an SQL ORDER BY clause without validation. This flaw gives low-privilege accounts the ability to execute time-based blind SQL injection attacks against the Koha database, potentially exposing sensitive patron information and staff credentials.
Affected Version(s)
Koha 0 <= 26.05.01-1
