Sale of a 0-Day Vulnerability Chain for Apache Fineract

Dark Web2026-08-31, 11:03
For informational purposes only.
Affected product: Apache Fineract 1.15.0 Vulnerability type: allegedly multiple authenticated SQL Injection vulnerabilities → database compromise / file read / DoS
The seller claims to be offering multiple 0-day vulnerabilities affecting Apache Fineract, an open-source core banking platform designed for banks, microfinance institutions, credit unions, fintech services, and other financial service providers. According to the seller, the vulnerabilities can be chained together, allowing a minimally privileged user to access data far beyond the scope of their assigned permissions.
The primary exploitation requirement, according to the seller, is any authenticated account with at least one read permission; administrative privileges are allegedly not required. The seller also mentions default credentials that may be present in certain standard or test Fineract deployments.
The claimed capabilities of the chain include full database exfiltration, including customer financial records, account balances, personal data, and password hashes. On MySQL/MariaDB deployments, the seller also claims the ability to read files accessible to the database service. Another scenario involves resource-intensive queries that could exhaust the database connection pool and disrupt service availability.
Notably, the seller’s description closely mirrors the impact of several recently disclosed Apache Fineract vulnerabilities. In July 2026, CVE-2026-35152, CVE-2026-56287, and CVE-2026-57821 were disclosed. These vulnerabilities allowed authenticated users to perform SQL injection, access data beyond their assigned permissions, read local files on MySQL/MariaDB deployments, and place heavy load on the database connection pool. All three affected Fineract 1.14.0 and earlier versions and were fixed in version 1.15.0.
The seller specifically claims that the proposed exploit chain still works against the latest version after the official patches have been applied. The current stable release of Apache Fineract is 1.15.0, released on July 11, 2026. This could indicate either new variants or patch bypasses for the recently fixed SQL injection vulnerabilities, or entirely separate flaws with similar impact.
Apache Fineract is a full-featured backend platform for digital financial services. It supports customer data management, lending and savings products, accounting, KYC, transactions, and other core banking functions. The project is part of the Apache Software Foundation and provides APIs that banks and fintech companies can use to build their own interfaces and services.
Apache Fineract has a notable global footprint, particularly among financial institutions. Apache states that the platform is used by hundreds of organizations across dozens of countries. The related Mifos ecosystem, which uses Apache Fineract as its backend, reports that solutions built on the platform have helped serve more than 20 million people worldwide, primarily through financial institutions, microfinance organizations, and fintech platforms.
Vulnerabilities
8.8
CVE-2026-35152
8.1
CVE-2026-56287
8.5
CVE-2026-57821
Researchers
Ádám Sághy
Aleksandar Vidakovic
Geo Chen
Quac Tran
Sanskaar Pathak
Terence Monteiro
More
Vendors
Apache Software Foundation
Products
Apache Fineract
Mariadb
Mifos
Mysql