Junglewise Threat Intelligence

CVE-2026-82232: Apache Syncope SQL injection in Task search

CVE-2026-82232 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Vendors: Apache.

Executive brief

Apache Syncope is an identity management platform used to manage user accounts and access across enterprises. Administrators with appropriate privileges can inject malicious SQL commands through unsanitized sort parameters in the Task search feature, potentially allowing unauthorized data access, modification, or system compromise.

Technical details

This is a SQL injection vulnerability (CWE-89) in the Task search functionality of Apache Syncope. The vulnerable component fails to properly sanitize sort clause parameters, allowing an authenticated administrator with sufficient entitlements to inject stacked SQL queries. The attack requires administrative privileges and network access to the application. An attacker can execute arbitrary SQL commands to read, modify, or delete data from the underlying database. Patches are available in versions 4.0.8, 4.1.3, and later.

Affected products

  • Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2

Timeline

  • 2026-09-14: disclosed

References