{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/evergreen/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-19926"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenSRF Service"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","sql-injection","cve-2026-19926"],"_cs_type":"advisory","_cs_vendors":["Evergreen"],"content_html":"\u003cp\u003eA critical SQL injection vulnerability, identified as CVE-2026-19926, exists in the OpenSRF Service component of the Evergreen integrated library system. The flaw specifically affects the '/osrf-gateway-v1' endpoint and arises from improper sanitization of user-supplied input. Publicly available exploit code currently exists, enabling remote, unauthenticated attackers to manipulate database queries. This vulnerability allows for unauthorized data access or modification within the back-end database of the Evergreen implementation. Affected installations include versions 3.14.11, 3.15.11, 3.16.5, and 3.17-beta1. Organizations should upgrade to versions 3.14.12, 3.15.12, 3.16.6, or 3.17-beta2 immediately to mitigate the risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits unauthorized actors to interact with the underlying database, potentially leading to full exfiltration of library records, user information, or system configuration data. Given the remote and unauthenticated nature of the attack, this represents a high risk to availability and confidentiality for institutions deploying the Evergreen system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Evergreen instances to version 3.14.12, 3.15.12, 3.16.6, or 3.17-beta2 immediately to remediate CVE-2026-19926.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering on the web server to restrict access to the '/osrf-gateway-v1' endpoint to only trusted internal IP ranges.\u003c/li\u003e\n\u003cli\u003eAudit database access logs for unusual patterns or syntax typical of SQL injection attempts, such as UNION statements or comment sequences, originating from the web server process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T02:22:45Z","date_published":"2026-08-16T02:22:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-evergreen-sql-injection/","summary":"Evergreen versions up to 3.17-beta1 contain a SQL injection vulnerability in the OpenSRF service, allowing remote unauthenticated attackers to execute arbitrary database queries.","title":"SQL Injection Vulnerability in Evergreen OpenSRF Service","url":"https://feed.craftedsignal.io/briefs/2026-08-evergreen-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Evergreen","version":"https://jsonfeed.org/version/1.1"}