SQL Injection Vulnerability in Apache Syncope Affecting Multiple Versions
CVE-2026-77051
Currently unrated
What is CVE-2026-77051?
An SQL Injection vulnerability exists in Apache Syncope, where an administrator with appropriate permissions can execute arbitrary SQL commands through stacked queries. This vulnerability arises due to unsanitized input in the entityKey and opEvent parameters. Users running affected versions are strongly advised to upgrade to the patched versions 4.0.8 or 4.1.3 to mitigate this security risk.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2