{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-56287","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2026-06-20T06:45:41.509Z","datePublished":"2026-07-15T09:19:38.262Z","dateUpdated":"2026-07-15T14:32:08.722Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache Fineract","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"1.14.0","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Anirudh Anand"},{"lang":"en","type":"reporter","value":"Aman Sapra"},{"lang":"en","type":"remediation developer","value":"Terence Monteiro (@terencemo)"},{"lang":"en","type":"remediation reviewer","value":"Ádám Sághy (@adamsaghy)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (<code>GET /api/v1/clients</code>) in versions up to and including 1.14.0. The <code>orderBy</code> and <code>sortOrder</code> request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted <code>orderBy</code> value. This can be leveraged to perform blind boolean-based data extraction and, on MySQL/MariaDB, to disclose arbitrary files readable by the database process via the <code>LOAD_FILE()</code> function. Users are recommended to upgrade to a version containing the fix"}],"value":"A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted orderBy value. This can be leveraged to perform blind boolean-based data extraction and, on MySQL/MariaDB, to disclose arbitrary files readable by the database process via the LOAD_FILE() function. Users are recommended to upgrade to a version containing the fix"}],"metrics":[{"other":{"content":{"text":"important"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2026-07-15T09:19:38.262Z"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/l5klcj2v0dx63bssvb0gmw1nzzc47col"},{"tags":["patch"],"url":"https://github.com/apache/fineract/pull/6020"}],"source":{"discovery":"EXTERNAL"},"title":"Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/07/15/2"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-07-15T09:40:33.186Z"}},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":8.1,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-07-15T14:32:04.391476Z","id":"CVE-2026-56287","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-15T14:32:08.722Z"}}]}}