securityonline.info 7/21/2026, 3:22:01 PM · external

Apache fixes three SQLi bugs in Fineract core banking software

Apache fixes three SQLi bugs in Fineract core banking software
CyberSIXT Evidence Panel
Primary Source fineract.apache.org
CISA KEV Not in KEV
Patch Patch Available

APACHE has fixed three SQL injection vulnerabilities in the open-source core banking platform Fineract, identified as CVE-2026-57821, CVE-2026-56287, and CVE-2026-35152. Each of these flaws exploits unvalidated query parameters and requires an authenticated user with specific permissions. Version 1.15.0 is confirmed to be unaffected, and no active exploitation has been reported. The vulnerabilities compromise sensitive financial data, allowing unauthorized data access and potential denial of service. Affected versions include up to 1.14.0, and users are advised to upgrade to version 1.15.0 and tighten permissions to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT