ZeroHour
ZDI Published Advisoriespublished ()ingested 1

ZDI-26-616: Koha Eval Code Injection Remote Code Execution Vulnerability

mediumVulnerabilityimportance 35CVE-2026-19780
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-19780, a CVSS 8.8 authenticated eval code-injection flaw in Koha enabling remote code execution.

Zero Day Initiative advisory ZDI-26-616 describes a code injection vulnerability in the Eval component of Koha, the open-source integrated library system. A remote attacker must authenticate before injecting and executing arbitrary code on affected installations. ZDI assigned the flaw a CVSS 3.0 rating of 8.8.

  • Remote code execution via eval code injection in Koha
  • Authentication is required for exploitation
  • CVSS 3.0 score of 8.8 assigned by ZDI
  • Affects Koha, an open-source library management platform

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-19780
Authenticated Eval Code Injection RCE in Koha Web Service (TCP 8081)

Koha, an open-source integrated library system, contains a code injection flaw (CWE-95) in a web service that listens on TCP port 8081 by default: a user-supplied string is passed to the eval function without proper validation. A remote attacker with valid authentication credentials can submit a crafted string to this service and execute arbitrary code in the context of the service account. Successful exploitation gives full compromise of confidentiality, integrity, and availability on the Koha server (CVSS 3.0: 8.8, high). Organizations running affected Koha deployments are at risk, particularly where port 8081 is reachable from untrusted networks; however, the authentication requirement limits attacks to holders of valid credentials. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not on the CISA KEV list.

Do: Apply the vendor patch specified in ZDI-26-616 (upgrade to the latest fixed Koha release). Restrict TCP 8081 at the firewall so the web service is reachable only from trusted staff/consortium networks, audit service accounts for weak or shared credentials, and review logs for unexpected code execution or anomalous activity under the service account.

8.8
  • Koha Community Koha (Integrated Library System)
moderate≈ thousands of library deployments globally (order of magnitude: low thousands of internet-visible Koha installations, with the 8081 service typically internal)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-19780.

This source does not provide full text. Read it at zerodayinitiative.com.