Threat Advisory

Apache Fineract SQL Injection Flaws Enable Data Disclosure and Denial of Service

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Apache has patched three SQL injection flaws in Fineract, the open-source core banking platform. The Apache Fineract SQL injection bugs, CVE-2026-57821, CVE-2026-56287, and CVE-2026-35152, all abuse unvalidated query parameters. Each requires an authenticated user with specific permissions. All three flaws affect Apache Fineract up to and including 1.14.0. Apache confirms that version 1.15.0 is not affected.

CVE-2026-57821 (CVSS 8.1 — High): The Office Search API concatenates the orderBy parameter into a SQL query, allowing an authenticated user to inject a subquery for time-based blind extraction, bypassing ColumnValidator fixes.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Apache has patched three SQL injection flaws in Fineract, the open-source core banking platform. The Apache Fineract SQL injection bugs, CVE-2026-57821, CVE-2026-56287, and CVE-2026-35152, all abuse unvalidated query parameters. Each requires an authenticated user with specific permissions. All three flaws affect Apache Fineract up to and including 1.14.0. Apache confirms that version 1.15.0 is not affected.

CVE-2026-57821 (CVSS 8.1 — High): The Office Search API concatenates the orderBy parameter into a SQL query, allowing an authenticated user to inject a subquery for time-based blind extraction, bypassing ColumnValidator fixes.[emaillocker id="1283"]

CVE-2026-56287 (CVSS 8.1 — High): The Client Search API mishandles the orderBy and sortOrder parameters, enabling an attacker on MySQL and MariaDB to call LOAD_FILE to read files the database process can access.

CVE-2026-35152 (CVSS 8.8 — High): The Report Execution API folds report parameter values into SQL without propermissions to reach data the report never intended to expose.

CVE-2024-32838: Which misses bare subqueries in the ORDER BY position. These vulnerabilities collectively present significant risks to confidentiality and availability of sensitive financial data. Administrators should apply the latest security updates now. These vulnerabilities collectively present significant risks to confidentiality and availability of sensitive financial data.

These vulnerabilities collectively present significant risks to confidentiality and availability of sensitive financial data.

RECOMMENDATION:

We recommend you to upgrade Apache Fineract to version 1.15.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu