CVE-2026-72607 | Koha Community up to 24.11.17/25.05.12/25.11.6/26.05.1 Automatic Item Modification ToggleNewStatus agefield sql injection

SecurityVulns

A vulnerability has been found in Koha Community Koha up to 24.11.17/25.05.12/25.11.6/26.05.1 and classified as critical. This vulnerability affects the function C4::Items::ToggleNewStatus of the component Automatic Item Modification. Performing a manipulation of the argument agefield results in sql injection.

This vulnerability was named CVE-2026-72607. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More