Koha Remote Code Execution Vulnerability Disclosed
Article Content
A remote code execution vulnerability has been identified in Koha, affecting installations that allow remote attackers to execute arbitrary code. The flaw requires authentication and exists within the web service listening on TCP port 8081. It stems from improper validation of user-supplied strings passed to the eval function, enabling attackers to execute code in the context of the service account. The vulnerability has been assigned the identifier ZDI-26-616 and is fixed in versions 26.11.00, 26.05.02, 25.11.07, 25.05.13, and 24.11.18. The vulnerability was reported to the vendor on April 7, 2026, and a coordinated public release of the advisory occurred on September 8, 2026. The advisory was updated the same day.
Key Points: • Vulnerability ZDI-26-616 allows remote code execution in Koha installations. • Authentication is required to exploit this vulnerability, which affects specific Koha versions. • The flaw is due to improper validation of user input in the web service's eval function.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.