CVE-2026-57821

HIGH

Apache Fineract: Office list: SQL Injection via Subquery in orderBy

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-57821. PoCs published by tc4dy.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-57821, a SQL injection vulnerability in Apache Fineract's API endpoint. The exploit demonstrates both time-based and error-based SQLi techniques to verify and exploit the vulnerability, enabling database enumeration and potential data exfiltration.

Description

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a bypass of the ColumnValidator fix introduced for CVE-2024-32838, which does not detect bare subqueries in the ORDER BY position. This can be leveraged to perform time-based blind SQL injection for data exfiltration. Because the injected query blocks the database connection for its full duration, concurrent exploitation can exhaust the application's database connection pool, resulting in denial of service for other users. Users are recommended to upgrade to a version containing the fix.

Exploits (1)

github WORKING POC
by tc4dy · pythonpoc
https://github.com/tc4dy/CVE-2026-57821-PoC-Exploit

This repository contains a functional proof-of-concept exploit for CVE-2026-57821, a SQL injection vulnerability in Apache Fineract's API endpoint. The exploit demonstrates both time-based and error-based SQLi techniques to verify and exploit the vulnerability, enabling database enumeration and potential data exfiltration.

Classification
Working Poc 98%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Apache Fineract (fineract-provider API)
Auth required
Prerequisites: Valid credentials for Apache Fineract · Network access to the Fineract API endpoint · Target must use a supported database backend (PostgreSQL, MySQL, MariaDB, MSSQL, Oracle, etc.)
mistral-large-3 · analyzed Jul 16, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 8.1
EPSS 0.0084
EPSS Percentile 54.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (3)
apache/fineract < 1.15.0
Apache Software Foundation/Apache Fineract < 1.14.0
Apache Software Foundation/Apache Fineract 1.15.0
Published Jul 15, 2026
Tracked Since Jul 15, 2026