Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Koha
Koha koha |
|
| CPEs | cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Koha
Koha koha |
Thu, 04 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Koha SSRF via Z39.50 Configuration Enables Internal Network Scanning |
Thu, 04 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in Koha v.25.11 and before allows a remote attacker to execute arbitrary code via the Z39.50 configuration module | Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server response times. |
Thu, 04 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Z39.50 Configuration in Koha | |
| Weaknesses | CWE-78 CWE-94 |
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 |
Thu, 04 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 03 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Z39.50 Configuration in Koha | |
| First Time appeared |
Koha-community
Koha-community koha |
|
| Weaknesses | CWE-78 CWE-94 |
|
| Vendors & Products |
Koha-community
Koha-community koha |
Wed, 03 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in Koha v.25.11 and before allows a remote attacker to execute arbitrary code via the Z39.50 configuration module | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-06-03T00:00:00.000Z
Updated: 2026-06-04T16:19:25.366Z
Reserved: 2026-02-16T00:00:00.000Z
Link: CVE-2026-26379
Updated: 2026-06-04T12:27:33.215Z
Status : Analyzed
Published: 2026-06-03T19:16:25.647
Modified: 2026-06-04T18:54:11.703
Link: CVE-2026-26379
No data.