<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Evergreen - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/evergreen/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 16 Aug 2026 02:22:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/evergreen/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in Evergreen OpenSRF Service</title><link>https://feed.craftedsignal.io/briefs/2026-08-evergreen-sql-injection/</link><pubDate>Sun, 16 Aug 2026 02:22:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-evergreen-sql-injection/</guid><description>Evergreen versions up to 3.17-beta1 contain a SQL injection vulnerability in the OpenSRF service, allowing remote unauthenticated attackers to execute arbitrary database queries.</description><content:encoded><![CDATA[<p>A critical SQL injection vulnerability, identified as CVE-2026-19926, exists in the OpenSRF Service component of the Evergreen integrated library system. The flaw specifically affects the '/osrf-gateway-v1' endpoint and arises from improper sanitization of user-supplied input. Publicly available exploit code currently exists, enabling remote, unauthenticated attackers to manipulate database queries. This vulnerability allows for unauthorized data access or modification within the back-end database of the Evergreen implementation. Affected installations include versions 3.14.11, 3.15.11, 3.16.5, and 3.17-beta1. Organizations should upgrade to versions 3.14.12, 3.15.12, 3.16.6, or 3.17-beta2 immediately to mitigate the risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability permits unauthorized actors to interact with the underlying database, potentially leading to full exfiltration of library records, user information, or system configuration data. Given the remote and unauthenticated nature of the attack, this represents a high risk to availability and confidentiality for institutions deploying the Evergreen system.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Evergreen instances to version 3.14.12, 3.15.12, 3.16.6, or 3.17-beta2 immediately to remediate CVE-2026-19926.</li>
<li>Implement strict ingress filtering on the web server to restrict access to the '/osrf-gateway-v1' endpoint to only trusted internal IP ranges.</li>
<li>Audit database access logs for unusual patterns or syntax typical of SQL injection attempts, such as UNION statements or comment sequences, originating from the web server process.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application-vulnerability</category><category>sql-injection</category><category>cve-2026-19926</category></item></channel></rss>