CVE-2026-35152

CVE-2026-35152: Apache Fineract: SQL injection in runreports endpoint

Vendor Apache Software Foundation
Product Apache Fineract
Weakness CWE-89 · SQLi
Published July 15, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. This can be leveraged to perform unauthorized access to data beyond what the report was designed to expose. Users are recommended to upgrade to a version containing the fix.

Key dates

02Disclosure timeline

July 15, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

04Related CVE