CVE-2026-19926: Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection
A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.14.12, 3.15.12, 3.16.6 and 3.17-beta2 is sufficient to fix this issue. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
open-ils.fielder OpenSRF Service osrf-gateway-v1to a version that resolves this vulnerability.Fixed in 3.14.12 - Upgrade
Upgrade
open-ils.fielder OpenSRF Service osrf-gateway-v1to a version that resolves this vulnerability.Fixed in 3.15.12 - Upgrade
Upgrade
open-ils.fielder OpenSRF Service osrf-gateway-v1to a version that resolves this vulnerability.Fixed in 3.16.6 - Upgrade
Upgrade
open-ils.fielder OpenSRF Service osrf-gateway-v1to a version that resolves this vulnerability.Fixed in 3.17-beta2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19926?
The severity of CVE-2026-19926 is high, rated at 7.3 on the CVSS scale.
How do I fix CVE-2026-19926?
To mitigate CVE-2026-19926, upgrade Evergreen to a version beyond 3.17-beta1.
What type of vulnerability is CVE-2026-19926?
CVE-2026-19926 is identified as a SQL Injection vulnerability.
Can CVE-2026-19926 be exploited remotely?
Yes, CVE-2026-19926 can be exploited remotely.
What component is affected by CVE-2026-19926?
CVE-2026-19926 affects the open-ils.fielder OpenSRF Service component.