SQL Injection Vulnerability in Apache Syncope by Apache
CVE-2026-82232

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82232?

An SQL injection vulnerability exists in Apache Syncope, allowing an authorized administrator to execute arbitrary SQL commands via unsanitized sort clauses. This exploit can be leveraged through stacked queries when performing Task searches. Users should upgrade to version 4.0.8 or 4.1.3 to mitigate this issue.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alon Galili
.