Apache Syncope: SQL injection vulnerability in Audit Events search
Published Jul 20, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.83%
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
Affected products
-
Affected
- ≥ 3.0.0-M0, ≤ 3.0.16
- ≥ 4.0.0-M0, ≤ 4.0.6
- ≥ 4.1.0-M0, ≤ 4.1.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache Syncope | unaffected | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- http://www.openwall.com/lists/oss-security/2026/07/20/8 Mailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45959 Advisory
- https://lists.apache.org/thread/g0gpctj90pbczbjl5jr33t8gr1gltg8v vendor-advisoryMailing ListVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/20/8 | Mailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45959 | Advisory | |
| https://lists.apache.org/thread/g0gpctj90pbczbjl5jr33t8gr1gltg8v | vendor-advisoryMailing ListVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data