πŸ” CVE Alert

CVE-2026-72610

MEDIUM 4.3

Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a time-based denial of service by storing a SQL payload in a patron lang field. The value is concatenated raw into a subquery in Koha::AdditionalContents->search_for_display when an issue slip is printed for the affected patron. The 25-character column length limits exploitation to timing attacks; data extraction is not practical. The stored payload executes on each subsequent issue-slip print, scaling linearly with the SLEEP value and the number of slip-news rows.

CWE CWE-89
Vendor koha community
Product koha
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for koha community koha

Be the first to know when new medium vulnerabilities affecting koha community koha are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Koha Community / Koha
0 < 24.11.18 25.05.0 < 25.05.13 25.11.0 < 25.11.07 26.05.0 < 26.05.02

References

NVD β†— CVE.org β†— EPSS Data β†—
bugs.koha-community.org: https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42866 koha-community.org: https://koha-community.org/

Credits

Sanjar Tulkinov Anvar ogΚ»li ([email protected])