Vulnerability Description
SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=199539
- https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42361
- https://koha-community.org/security-releases/
FAQ
What is CVE-2026-6428?
CVE-2026-6428 is a vulnerability with a CVSS score of 7.6 (HIGH). SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x be...
How severe is CVE-2026-6428?
CVE-2026-6428 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-6428?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.