A vulnerability was found in Koha Community Koha up to 24.11.17/25.05.12/25.11.06/26.05.01 and classified as critical. This issue affects some unknown processing of the file patroncards/create-pdf.pl. Executing a manipulation of the argument image_name can lead to sql injection.
The identification of this vulnerability is CVE-2026-72608. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.