Apache · Apache Fineract · CVE-2026-35152
**Name of the Vulnerable Software and Affected Versions**
Apache Fineract versions prior to 1.14.1
**Description**
An issue exists in the Report Execution API 'runreports' endpoint where report parameter values are incorporated into the generated SQL query without sufficient validation. This allows an authenticated user with report execution permissions to inject arbitrary SQL through crafted parameter values, potentially leading to unauthorized access to data beyond the intended scope of the report.
**Recommendations**
Upgrade to a version containing the fix.
Restrict the use of the 'runreports' endpoint for users with excessive permissions until the update is applied.