Stored SQL Injection Vulnerability in Koha Library Management System
CVE-2026-72610
What is CVE-2026-72610?
A stored SQL injection vulnerability in the Koha Library Management System allows authenticated staff members with specific permissions to introduce a SQL payload into a patron's language field. This vulnerability, present in several specified versions, enables time-based denial of service attacks when the issue slip is printed. The SQL insertion is executed on every subsequent print, leading to performance degradation with each operation. The constraint on the column length limits the attack to timing attacks, making data extraction impractical. This vulnerability necessitates prompt attention to patch the system and prevent potential disruptions in service.
Affected Version(s)
Koha 0 < 24.11.18
Koha 25.05.0 < 25.05.13
Koha 25.11.0 < 25.11.07
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
