CVE-2026-57821
Apache Software Foundation Apache Fineract, fineract
A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a bypass of the ColumnValidator fix introduced for CVE-2024-32838, which does not detect bare subqueries in the ORDER BY position. This can be leveraged to perform time-based blind SQL injection for data exfiltration. Because the injected qu...
- CVSS
- 8.1
- EPSS
- 0.79% 52.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.15