What is CVE-2026-19926?
A SQL injection vulnerability has been identified in the OpenSRF service of the Evergreen library system. This allows remote attacks via `/osrf-gateway-v1`, affecting versions up to 3.14.11, 3.15.11, 3.16.5, and 3.17-beta1. Immediate software update is recommended.
Azərbaycanca: Evergreen kitabxana sisteminin OpenSRF xidmətində SQL injection zəifliyi aşkarlanıb. Bu, `/osrf-gateway-v1` üzərindən uzaqdan hücum etməyə imkan verir və təsirlənən versiyalara 3.14.11, 3.15.11, 3.16.5 və 3.17-beta1 daxildir. Dərhal proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What system is affected by CVE-2026-19926?
This vulnerability affects the OpenSRF service of the Evergreen library system.
Which versions are considered affected by CVE-2026-19926?
The affected versions include 3.14.11, 3.15.11, 3.16.5, and 3.17-beta1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.