Apache disclosed CVE-2026-56287, an important-severity vulnerability in Apache Fineract that allows an authenticated user to exploit the Client Search API through insufficient validation of the orderBy and sortOrder parameters in GET /api/v1/clients. The flaw affects Fineract 1.14.0 and earlier affected releases, while 1.15.0 is listed as unaffected. An attacker must have permission to view clients to trigger the issue.
Successful exploitation can enable blind boolean-based SQL injection for arbitrary data extraction, and in deployments using MySQL or MariaDB, it can also expose local files via the database LOAD_FILE() function. Apache Fineract, a platform used for digital financial services, advised users to upgrade to a fixed release to mitigate the risk of database compromise and local file disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
In the disclosure, Apache stated that Fineract 1.15.0 is unaffected by CVE-2026-56287 and advised users to upgrade to a fixed version. This establishes the remediation guidance associated with the vulnerability announcement.
Apache disclosed CVE-2026-56287, an important-severity boolean-based SQL injection vulnerability in Apache Fineract's GET /api/v1/clients endpoint. The flaw affects Apache Fineract 1.14.0 and earlier affected releases and can allow blind boolean-based data extraction and, on MySQL or MariaDB, local file disclosure via LOAD_FILE().
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.