---
id: CVE-2026-6428
title: >-
  SQL Injection in reports/catalogue_out.pl in Koha Community Koha through
  22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before
  25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an
  authenticated…
summary: >-
  SQL Injection in reports/catalogue_out.pl in Koha Community Koha through
  22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before
  25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an
  authenticated…
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'
cwe:
  - CWE-89
published: '2026-06-13'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6428'
references:
  - url: 'https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=199539'
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
  - url: 'https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42361'
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
  - url: 'https://koha-community.org/security-releases/'
    label: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
tags:
  - nvd
epss: 0.00244
epssPercentile: 0.15919
ingestedAt: '2026-08-10T12:39:46.654Z'
---

## Overview

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
