---
id: CVE-2026-19780
title: Koha Eval Code Injection Remote Code Execution Vulnerability
summary: >-
  Koha Eval Code Injection Remote Code Execution Vulnerability. This
  vulnerability allows remote attackers to execute arbitrary code on affected
  installations of Koha. Authentication is required to exploit this
  vulnerability.


  The specific…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-95
vendor: Koha
product: Koha
affected:
  - Koha 25.12.00
published: '2026-09-15'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T18:17:12.520'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19780'
references:
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-26-616/'
    label: zdi-disclosures@trendmicro.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T17:56:38.910000Z'
epss: 0.00584
epssPercentile: 0.4553
zeroDay: true
ingestedAt: '2026-09-15T16:40:03.399Z'
---

## Overview

Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability.

The specific flaw exists within the web service, which listens on TCP port 8081 by default. The issue results from the lack of proper validation of a user-supplied string before passing it to the eval function. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-29165.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
