Junglewise Threat Intelligence

CVE-2026-72608: Koha stored SQL injection in patron card layout

CVE-2026-72608 · Severity: medium · CVSS 6.5 · Published 2026-08-11

Technologies: Koha.

Executive brief

Koha is a free and open-source library management system used by thousands of libraries worldwide to manage patron records, circulation, and catalog data. A stored SQL injection vulnerability allows authenticated library staff with patron card creation privileges to inject malicious SQL commands that can be triggered when printing patron cards, potentially exposing the entire database including patron personal information, staff passwords, and other sensitive library data.

Technical details

This is a stored (second-order) SQL injection vulnerability in Koha's patron card module (CWE-89). The vulnerability exists in two stages: (1) During layout creation (patroncards/edit-layout.pl), user-supplied image_name parameters are stored verbatim into layout XML without validation or escaping; (2) During card printing (patroncards/create-pdf.pl), the stored image_name value is concatenated directly into a SQL query without parameterization. An authenticated staff member with the tools/label_creator permission can exploit this by storing SQL injection payloads in the image_name field, then triggering execution by printing a patron card batch using that layout. Attackers can extract arbitrary database contents including borrower PII and staff password hashes using error-based or time-based blind SQL injection techniques. Patches are available in versions 26.11.00, 26.05.02, 25.11.07, 25.05.13, and 24.11.18.

Affected products

  • Koha Koha through 24.11.17, 25.05.12, 25.11.06, 26.05.01

Timeline

  • 2026-08-11: disclosed
  • 2026-09-03: patched: Fixes released in versions 26.11.00, 26.05.02, 25.11.07, 25.05.13, 24.11.18

References