CVE-2026-6428: Koha Community Koha

High severity, CVSS 7.6. EPSS: 0.4% chance of exploitation in the next 30 days.

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.

Affected products

  • Koha Community Koha: up to and including 22.11.38; from 23.05.00, up to and including 23.11.15; from 24.05.00, up to and including 24.11.16; from 25.05.00, up to and including 25.05.11; from 25.11.00, up to and including 25.11.05; from 26.05.00, up to and including 26.05.01

Published 2026-06-13. Last modified 2026-08-10.