CVE-2026-72610: CWE-89: Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) in Koha Community Koha
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a time-based denial of service by storing a SQL payload in a patron lang field. The value is concatenated raw into a subquery in Koha::AdditionalContents->search_for_display when an issue slip is printed for the affected patron. The 25-character column length limits exploitation to timing attacks; data extraction is not practical. The stored payload executes on each subsequent issue-slip print, scaling linearly with the SLEEP value and the number of slip-news rows.
AI Analysis
Technical Summary
This vulnerability (CWE-89) allows authenticated staff members with specific permissions in Koha Community versions 25.05.0, 25.11.0, and 26.05.0 to store a SQL injection payload in a patron language field. The payload is concatenated without proper neutralization into a subquery within Koha::AdditionalContents->search_for_display during issue slip printing. Due to the 25-character limit on the column, exploitation is restricted to time-based denial of service attacks rather than data extraction. Each time an issue slip is printed for the affected patron, the stored payload executes, causing delays that scale linearly with the injected SLEEP value and the number of slip-news rows.
Potential Impact
The vulnerability enables a time-based denial of service attack that can degrade system performance when issue slips are printed for affected patrons. There is no confidentiality or integrity impact reported, and data extraction is not practical due to input length constraints. The attack requires authenticated staff privileges with the borrowers => edit_borrowers permission.
Mitigation Recommendations
No official patch or remediation is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict or review staff permissions to limit who can edit borrower information, especially the language field. Monitor for unusual delays during issue slip printing as a potential indicator of exploitation.
CVE-2026-72610: CWE-89: Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) in Koha Community Koha
Description
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a time-based denial of service by storing a SQL payload in a patron lang field. The value is concatenated raw into a subquery in Koha::AdditionalContents->search_for_display when an issue slip is printed for the affected patron. The 25-character column length limits exploitation to timing attacks; data extraction is not practical. The stored payload executes on each subsequent issue-slip print, scaling linearly with the SLEEP value and the number of slip-news rows.
CVSS v3.1
Score 4.3medium
Affected software
pkg:github/koha-community/KohaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-89) allows authenticated staff members with specific permissions in Koha Community versions 25.05.0, 25.11.0, and 26.05.0 to store a SQL injection payload in a patron language field. The payload is concatenated without proper neutralization into a subquery within Koha::AdditionalContents->search_for_display during issue slip printing. Due to the 25-character limit on the column, exploitation is restricted to time-based denial of service attacks rather than data extraction. Each time an issue slip is printed for the affected patron, the stored payload executes, causing delays that scale linearly with the injected SLEEP value and the number of slip-news rows.
Potential Impact
The vulnerability enables a time-based denial of service attack that can degrade system performance when issue slips are printed for affected patrons. There is no confidentiality or integrity impact reported, and data extraction is not practical due to input length constraints. The attack requires authenticated staff privileges with the borrowers => edit_borrowers permission.
Mitigation Recommendations
No official patch or remediation is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict or review staff permissions to limit who can edit borrower information, especially the language field. Monitor for unusual delays during issue slip printing as a potential indicator of exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-10T10:33:03.258Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7b0a86bf8831d539a55f34
Added to database: 08/11/2026, 11:41:58 UTC
Last enriched: 08/11/2026, 11:57:27 UTC
Last updated: 08/11/2026, 12:27:05 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.