CVE-2026-71288: CWE-89 in Koha Community Koha
Koha Community Koha contains a SQL injection vulnerability in its guided report builder. The vulnerability arises because the application concatenates user-supplied parameters directly into an SQL ORDER BY clause without validation or an allowlist. This flaw allows any staff member with create_reports or execute_reports permissions to perform time-based blind SQL injection attacks. The database stores sensitive patron and staff information, including PII and credentials. No official patch or remediation guidance is currently available.
AI Analysis
Technical Summary
The guided report builder in Koha Community Koha (reports/guided_reports.pl) reads the 'order_by' CGI parameter and dynamically constructs an SQL ORDER BY clause by concatenating user-supplied values without validation or an allowlist. Since ORDER BY columns cannot be safely parameterized in prepared statements, the lack of validation enables SQL injection. Staff accounts with low-privilege permissions (create_reports or execute_reports) can exploit this to perform time-based blind SQL injection against the Koha database, which contains patron personally identifiable information and staff/LDAP credentials. The vulnerability is tracked as CVE-2026-71288 with a CVSS 3.1 score of 8.8 (high severity). No patch or official remediation is currently documented.
Potential Impact
Exploitation of this vulnerability allows an attacker with low-privilege staff access to execute arbitrary SQL commands via time-based blind SQL injection. This can lead to unauthorized disclosure, modification, or deletion of sensitive data including patron PII and staff credentials, potentially compromising confidentiality, integrity, and availability of the Koha database.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict or review staff permissions related to create_reports and execute_reports to trusted personnel only. Monitor for unusual report-building activity and consider additional application-layer controls to validate or restrict input parameters used in SQL queries.
CVE-2026-71288: CWE-89 in Koha Community Koha
Description
Koha Community Koha contains a SQL injection vulnerability in its guided report builder. The vulnerability arises because the application concatenates user-supplied parameters directly into an SQL ORDER BY clause without validation or an allowlist. This flaw allows any staff member with create_reports or execute_reports permissions to perform time-based blind SQL injection attacks. The database stores sensitive patron and staff information, including PII and credentials. No official patch or remediation guidance is currently available.
CVSS v3.1
Score 8.8high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The guided report builder in Koha Community Koha (reports/guided_reports.pl) reads the 'order_by' CGI parameter and dynamically constructs an SQL ORDER BY clause by concatenating user-supplied values without validation or an allowlist. Since ORDER BY columns cannot be safely parameterized in prepared statements, the lack of validation enables SQL injection. Staff accounts with low-privilege permissions (create_reports or execute_reports) can exploit this to perform time-based blind SQL injection against the Koha database, which contains patron personally identifiable information and staff/LDAP credentials. The vulnerability is tracked as CVE-2026-71288 with a CVSS 3.1 score of 8.8 (high severity). No patch or official remediation is currently documented.
Potential Impact
Exploitation of this vulnerability allows an attacker with low-privilege staff access to execute arbitrary SQL commands via time-based blind SQL injection. This can lead to unauthorized disclosure, modification, or deletion of sensitive data including patron PII and staff credentials, potentially compromising confidentiality, integrity, and availability of the Koha database.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict or review staff permissions related to create_reports and execute_reports to trusted personnel only. Monitor for unusual report-building activity and consider additional application-layer controls to validate or restrict input parameters used in SQL queries.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-05T12:23:34.968Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7336e7bf8831d539ed92f2
Added to database: 08/05/2026, 13:13:11 UTC
Last enriched: 08/05/2026, 13:26:54 UTC
Last updated: 08/05/2026, 13:26:54 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.