SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-57821

HIGH · CVSS 8.1 EPSS 0.84% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Office Search API in Apache Fineract versions up to 1.14.0 is vulnerable to SQL Injection due to insufficient validation of the orderBy request parameter, allowing authenticated users to execute arbitrary SQL queries. This vulnerability can lead to data exfiltration and potential denial of service by exhausting the database connection pool. Organizations using affected versions should prioritize upgrading to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57821
Severity
HIGH
CVSS
8.1
EPSS
0.84%
Office Apache

Original NVD Description

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a bypass of the ColumnValidator fix introduced for CVE-2024-32838, which does not detect bare subqueries in the ORDER BY position. This can be leveraged to perform time-based blind SQL injection for data exfiltration. Because the injected query blocks the database connection for its full duration, concurrent exploitation can exhaust the application's database connection pool, resulting in denial of service for other users. Users are recommended to upgrade to a version containing the fix.

Related CVEs

Other vulnerabilities affecting the same vendor(s)