ThreatCluster

Koha Remote Code Execution Vulnerability Disclosed

First seen 10 Sep 2026, 14:45 UTC Zerodayinitiativewww.zerodayinitiative.com 46

Article Content

Browse articles
ThreatCluster

A remote code execution vulnerability has been identified in Koha, affecting installations that allow remote attackers to execute arbitrary code. The flaw requires authentication and exists within the web service listening on TCP port 8081. It stems from improper validation of user-supplied strings passed to the eval function, enabling attackers to execute code in the context of the service account. The vulnerability has been assigned the identifier ZDI-26-616 and is fixed in versions 26.11.00, 26.05.02, 25.11.07, 25.05.13, and 24.11.18. The vulnerability was reported to the vendor on April 7, 2026, and a coordinated public release of the advisory occurred on September 8, 2026. The advisory was updated the same day.

Key Points: • Vulnerability ZDI-26-616 allows remote code execution in Koha installations. • Authentication is required to exploit this vulnerability, which affects specific Koha versions. • The flaw is due to improper validation of user input in the web service's eval function.

Ask AI about this cluster

Timeline

2026-04-07
Vulnerability reported to vendor
The Koha vulnerability was reported to the vendor, initiating the disclosure process.
Zerodayinitiative
2026-09-08
Coordinated public release of advisory
The advisory detailing the Koha vulnerability was publicly released, informing users of the issue.
Zerodayinitiative
2026-09-08
Advisory updated
The advisory was updated on the same day to provide further details on the vulnerability.
Zerodayinitiative