Apache Syncope SQL Injection Vulnerability in Audit Events Search

Vulnerability

A SQL injection vulnerability has been identified in Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. This vulnerability allows an administrator with the appropriate entitlements to execute arbitrary SQL by using stacked queries, taking advantage of unsanitized sort parameters.

Impact

Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation.

Remediation

Users are advised to upgrade to Apache Syncope version 4.0.7 or 4.1.2, both of which address this vulnerability.

Added: Jul 20, 2026, 3:31 PM
Updated: Jul 20, 2026, 3:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.8
remediation
0.0
relevance
10.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.