Junglewise Threat Intelligence

CVE-2026-6428: Koha Community Koha SQL injection in reports/catalogue_out.pl

CVE-2026-6428 · Severity: high · CVSS 7.6 · Published 2026-06-13

Technologies: Koha Community Koha. Vendors: Koha Community.

Executive brief

Koha, a widely used open-source library management system, contains a security vulnerability in its reporting module. An authorized staff member can exploit this flaw to bypass security controls and access sensitive information stored in the library's database. This includes personal data of library patrons, staff password hashes, and administrative API keys, potentially leading to full account takeovers or data breaches.

Technical details

A SQL injection vulnerability exists in Koha's 'Items with no checkouts' report (reports/catalogue_out.pl). The root cause is the direct concatenation of the 'Filter' URL parameter into a SQL LIKE clause within the 'calculate' subroutine when the 'Criteria' parameter matches 'branchcode'. An authenticated staff user with 'reports' module permissions can use error-based SQL injection techniques (such as EXTRACTVALUE) to exfiltrate data from sensitive tables, including 'borrowers' (PII and hashes), 'sessions', and 'api_keys'. The vulnerability was introduced in 2008 and remained unpatched despite similar fixes in sibling files in 2015. It has been resolved in versions 22.11.38, 24.11.16, 25.05.11, 25.11.05, 26.05.01, and 26.11.00 by implementing parameterized queries.

Affected products

  • Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, 26.11.x before 26.11.00

Timeline

  • 2026-04-14: disclosed: Vulnerability reported to Koha Community via Bugzilla.
  • 2026-06-09: patched: Security releases 22.11.38, 24.11.16, 25.05.11, 25.11.05 published.
  • 2026-06-13: advisory: CVE-2026-6428 published.

References

Related threats