SQL Injection Vulnerability in Apache Syncope by Apache
CVE-2026-82232
Currently unrated
What is CVE-2026-82232?
An SQL injection vulnerability exists in Apache Syncope, allowing an authorized administrator to execute arbitrary SQL commands via unsanitized sort clauses. This exploit can be leveraged through stacked queries when performing Task searches. Users should upgrade to version 4.0.8 or 4.1.3 to mitigate this issue.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2