8.8

CVE-2026-35152

Apache Fineract: SQL injection in runreports endpoint

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. This can be leveraged to perform unauthorized access to data beyond what the report was designed to expose. Users are recommended to upgrade to a version containing the fix.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Fineract Version < 1.15.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.28% 0.813
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://github.com/apache/fineract/pull/5980
Patch
https://lists.apache.org/thread/d3bzcwsbywz7wg9zxvtlkvgmffqjyfn0
Vendor Advisory
Mailing List
https://lists.apache.org/thread/658yddn0bpxqw2hpxnyk3vqd05bkchg9
Vendor Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2026/07/15/1
Third Party Advisory
Mailing List