


Perceptive Security
SOC/SIEM Consultancy

Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and, for each value, a dynamically-named `{order}_ovalue` parameter,…
Published:
4 augustus 2026 om 22:00:00
Alert date:
5 augustus 2026 om 14:10:56
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Database & Storage, Identity & Access
CVE-2026-71288 describes a SQL injection vulnerability in Koha's guided report builder (reports/guided_reports.pl). The flaw arises from unsanitized concatenation of the 'order_by' CGI parameter and a dynamically-named '{order}_ovalue' parameter directly into an SQL ORDER BY clause. No allowlist or validation is applied, and because ORDER BY clauses cannot use prepared-statement placeholders, the vulnerability cannot be mitigated by standard parameterization alone. Any staff account holding the low-privilege 'create_reports' or 'execute_reports' permission can exploit this to perform time-based blind SQL injection. The Koha database contains sensitive patron PII as well as staff and LDAP credentials, making successful exploitation high-impact. This affects library management systems running vulnerable Koha versions globally.
Technical details
Mitigation steps:
Affected products:
Koha Library Management System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-71288
https://github.com/Koha-Community/Koha
https://github.com/Koha-Community/Koha/blob/master/reports/guided_reports.pl
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
