https://seclists.org/oss-sec/2026/q3/148: CVE-2026-56287: Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosu
Published Jul 15, 2026
·Updated
Affected Software
1 affected component
Apache Fineract<=1.14.0
Frequently Asked Questions
1
What is the severity of CVE-2026-56287?
The severity of CVE-2026-56287 is classified as important.
2
Which versions of Apache Fineract are affected by CVE-2026-56287?
Apache Fineract versions 1.14.0 and 1.15.0 are affected by CVE-2026-56287.
3
What type of vulnerability is CVE-2026-56287?
CVE-2026-56287 is a boolean SQL injection vulnerability found in the Client Search API.
4
How can I mitigate the effects of CVE-2026-56287?
To mitigate CVE-2026-56287, it is advisable to upgrade to the latest version of Apache Fineract that is unaffected.
5
What exploit could result from CVE-2026-56287?
CVE-2026-56287 could lead to local file disclosure due to the SQL injection vulnerability.