CVE-2026-26377: XSS
Published Mar 5, 2026
·Updated
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.
Affected Software
2 affected components
koha/koha<25.11
Koha Koha<=25.11.00
Event History
Mar 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26377?
CVE-2026-26377 has been assessed to have a high severity due to the potential for remote code execution.
2
How do I fix CVE-2026-26377?
To fix CVE-2026-26377, upgrade Koha to version 25.12 or later.
3
What impact does CVE-2026-26377 have on users?
CVE-2026-26377 allows attackers to execute arbitrary code, potentially compromising user data and system integrity.
4
Is CVE-2026-26377 exploitable without authentication?
Yes, CVE-2026-26377 can be exploited by remote attackers without requiring authentication.
5
Which versions of Koha are affected by CVE-2026-26377?
Koha versions 25.11 and earlier are vulnerable to CVE-2026-26377.