CVE-2026-35152: Apache Fineract: SQL injection in runreports endpoint
A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. This can be leveraged to perform unauthorized access to data beyond what the report was designed to expose. Users are recommended to upgrade to a version containing the fix.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Fineractto a version that resolves this vulnerability.Fixed in 1.14.0Patch CVE-2026-35152 - Upgrade
Upgrade
Apache Fineractto a version that resolves this vulnerability.Patch CVE-2026-35152
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35152?
CVE-2026-35152 has a high severity rating of 8.8 according to CVSS 3.1 metrics.
How do I fix CVE-2026-35152?
To fix CVE-2026-35152, upgrade Apache Fineract to version 1.14.1 or later.
What kind of vulnerability is CVE-2026-35152?
CVE-2026-35152 is a SQL Injection vulnerability affecting the runreports endpoint in Apache Fineract.
Who is affected by CVE-2026-35152?
Authenticated users with permission to execute reports in Apache Fineract versions up to and including 1.14.0 are affected by CVE-2026-35152.
When was CVE-2026-35152 published?
CVE-2026-35152 was published on July 15, 2026.