APACHE has fixed three SQL injection vulnerabilities in the open-source core banking platform Fineract, identified as CVE-2026-57821, CVE-2026-56287, and CVE-2026-35152. Each of these flaws exploits unvalidated query parameters and requires an authenticated user with specific permissions. Version 1.15.0 is confirmed to be unaffected, and no active exploitation has been reported. The vulnerabilities compromise sensitive financial data, allowing unauthorized data access and potential denial of service. Affected versions include up to 1.14.0, and users are advised to upgrade to version 1.15.0 and tighten permissions to mitigate risks.
Apache fixes three SQLi bugs in Fineract core banking software
CyberSIXT Evidence Panel
Article by CyberSIXT