Description
A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.14.12, 3.15.12, 3.16.6 and 3.17-beta2 is sufficient to fix this issue. The affected component should be upgraded.
Published: 2026-08-16
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Evergreen version releases up to 3.14.11, 3.15.11, 3.16.5 and 3.17-beta1 contain an undisclosed function in the open-ils.fielder OpenSRF Service that accepts unsanitized input and allows a crafted input to inject arbitrary SQL commands. This flaw can be leveraged to read, modify, delete, or possibly execute database commands, thereby compromising the confidentiality, integrity, or availability of the database contents and, depending on the database configuration, could lead to remote code execution. The vulnerability is classified as an SQL injection (CWE‑89) and is accessible through the /osrf-gateway-v1 endpoint.

Affected Systems

All Evergreen installations running 3.14.11 or older, 3.15.11 or older, 3.16.5 or older, and 3.17-beta1 or older are affected. The vendor has released patch versions 3.14.12, 3.15.12, 3.16.6 and 3.17-beta2 that fix the injection issue; updating to at least these versions is required to remediate.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity vulnerability. No EPSS score is reported, but the flaw has been publicly disclosed and the exploit is known to be usable remotely, which increases practical risk. Because the compromised interface is reachable over the network, an attacker can reach it from remote systems. The vulnerability is not listed in the CISA KEV catalog, but its remote nature and potential for data loss or code compromise make rapid mitigation critical.

Generated by OpenCVE AI on August 16, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Evergreen to version 3.14.12, 3.15.12, 3.16.6 or 3.17-beta2 to eliminate the injection flaw.
  • If a patch cannot be applied immediately, limit network exposure by restricting access to the open-ils.fielder OpenSRF Service to trusted hosts only.
  • Apply least‑privilege database permissions to the service account to minimize the impact of any future injection attempts.

Generated by OpenCVE AI on August 16, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.14.12, 3.15.12, 3.16.6 and 3.17-beta2 is sufficient to fix this issue. The affected component should be upgraded.
Title Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection
First Time appeared Evergreen
Evergreen evergreen
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:evergreen:evergreen:*:*:*:*:*:*:*:*
Vendors & Products Evergreen
Evergreen evergreen
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Evergreen Evergreen
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-16T01:45:19.700Z

Reserved: 2026-08-15T05:32:13.802Z

Link: CVE-2026-19926

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-16T02:16:48.790

Modified: 2026-08-16T02:16:48.790

Link: CVE-2026-19926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T03:30:06Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')