Evergreen · Evergreen · CVE-2026-19926
**Name of the Vulnerable Software and Affected Versions**
Evergreen versions prior to 3.14.12
Evergreen versions prior to 3.15.12
Evergreen versions prior to 3.16.6
Evergreen versions prior to 3.17-beta2
**Description**
A remote SQL injection exists within the open-ils.fielder OpenSRF Service, specifically affecting a function in the `/osrf-gateway-v1` file. SQL injection is a technique where an attacker inserts malicious SQL code into a query, allowing them to manipulate the database.
**Recommendations**
Upgrade to version 3.14.12.
Upgrade to version 3.15.12.
Upgrade to version 3.16.6.
Upgrade to version 3.17-beta2.