Executive brief
Apache Syncope is an identity and access management platform used to provision and manage user accounts across enterprise systems. An authenticated administrator can inject arbitrary SQL commands through unsanitized input parameters, potentially reading or modifying sensitive identity data, creating unauthorized accounts, or disrupting identity services.
Technical details
This SQL injection vulnerability exists in Apache Syncope due to improper sanitization of the entityKey and opEvent parameters, allowing an authenticated administrator to execute stacked SQL queries. The vulnerability affects versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Exploitation requires valid administrator credentials with adequate entitlements to access the affected parameters. An attacker with these privileges can execute arbitrary SQL commands to read, modify, or delete data in the backend database. Apache has released patches in versions 4.0.8 and 4.1.3 to address this issue.
Affected products
- Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2
Timeline
- 2026-09-14: disclosed