CVE-2026-35152

fineract: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CVE-2026-35152)

Description

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. This can be leveraged to perform unauthorized access to data beyond what the report was designed to expose. Users are recommended to upgrade to a version containing the fix.

Source: CVELISTV5NVD

Metrics

Severity
high
no public PoC known
8.8
Source: nvd-v3
87.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
3.3 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-07-15 09:19 UTC
CWE-89

Weakness classes (CWE)

  • CWE-89Base

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • apache

    fineract1.15.0

References & sources

IDCVE-2026-35152