Stored SQL Injection Vulnerability in Koha Library Management System
CVE-2026-72610

4.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72610?

A stored SQL injection vulnerability in the Koha Library Management System allows authenticated staff members with specific permissions to introduce a SQL payload into a patron's language field. This vulnerability, present in several specified versions, enables time-based denial of service attacks when the issue slip is printed. The SQL insertion is executed on every subsequent print, leading to performance degradation with each operation. The constraint on the column length limits the attack to timing attacks, making data extraction impractical. This vulnerability necessitates prompt attention to patch the system and prevent potential disruptions in service.

Affected Version(s)

Koha 0 < 24.11.18

Koha 25.05.0 < 25.05.13

Koha 25.11.0 < 25.11.07

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sanjar Tulkinov Anvar ogʻli (sanjarbiy11@gmail.com)
.