CVE-2026-57821
HIGHApache Fineract: Office list: SQL Injection via Subquery in orderBy
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-57821. PoCs published by tc4dy.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-57821, a SQL injection vulnerability in Apache Fineract's API endpoint. The exploit demonstrates both time-based and error-based SQLi techniques to verify and exploit the vulnerability, enabling database enumeration and potential data exfiltration.
Description
A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a bypass of the ColumnValidator fix introduced for CVE-2024-32838, which does not detect bare subqueries in the ORDER BY position. This can be leveraged to perform time-based blind SQL injection for data exfiltration. Because the injected query blocks the database connection for its full duration, concurrent exploitation can exhaust the application's database connection pool, resulting in denial of service for other users. Users are recommended to upgrade to a version containing the fix.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2026-57821, a SQL injection vulnerability in Apache Fineract's API endpoint. The exploit demonstrates both time-based and error-based SQLi techniques to verify and exploit the vulnerability, enabling database enumeration and potential data exfiltration.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H