CVE-2026-72607 | Koha Community up to 24.11.17/25.05.12/25.11.6/26.05.1 Automatic Item Modification ToggleNewStatus agefield sql injection
A vulnerability has been found in Koha Community Koha up to 24.11.17/25.05.12/25.11.6/26.05.1 and classified as critical. This vulnerability affects the function C4::Items::ToggleNewStatus of the component Automatic Item Modification. Performing a manipulation of the argument agefield results in sql injection.
This vulnerability was named CVE-2026-72607. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More