Apache has patched three SQL injection flaws in Fineract, the open-source core banking platform. The Apache Fineract SQL injection bugs, CVE-2026-57821, CVE-2026-56287, and CVE-2026-35152, all abuse unvalidated query parameters. Each requires an authenticated user with specific permissions. All three flaws affect Apache Fineract up to and including 1.14.0. Apache confirms that version 1.15.0 is not affected.
CVE-2026-57821 (CVSS 8.1 — High): The Office Search API concatenates the orderBy parameter into a SQL query, allowing an authenticated user to inject a subquery for time-based blind extraction, bypassing ColumnValidator fixes.[/subscribe_to_unlock_form]
Apache has patched three SQL injection flaws in Fineract, the open-source core banking platform. The Apache Fineract SQL injection bugs, CVE-2026-57821, CVE-2026-56287, and CVE-2026-35152, all abuse unvalidated query parameters. Each requires an authenticated user with specific permissions. All three flaws affect Apache Fineract up to and including 1.14.0. Apache confirms that version 1.15.0 is not affected.
CVE-2026-57821 (CVSS 8.1 — High): The Office Search API concatenates the orderBy parameter into a SQL query, allowing an authenticated user to inject a subquery for time-based blind extraction, bypassing ColumnValidator fixes.[emaillocker id="1283"]
CVE-2026-56287 (CVSS 8.1 — High): The Client Search API mishandles the orderBy and sortOrder parameters, enabling an attacker on MySQL and MariaDB to call LOAD_FILE to read files the database process can access.
CVE-2026-35152 (CVSS 8.8 — High): The Report Execution API folds report parameter values into SQL without propermissions to reach data the report never intended to expose.
CVE-2024-32838: Which misses bare subqueries in the ORDER BY position. These vulnerabilities collectively present significant risks to confidentiality and availability of sensitive financial data. Administrators should apply the latest security updates now. These vulnerabilities collectively present significant risks to confidentiality and availability of sensitive financial data.
These vulnerabilities collectively present significant risks to confidentiality and availability of sensitive financial data.
We recommend you to upgrade Apache Fineract to version 1.15.0.
The following reports contain further technical details:
[/emaillocker]