Executive brief
Apache Syncope is an identity management platform used to manage user accounts and access across enterprises. Administrators with appropriate privileges can inject malicious SQL commands through unsanitized sort parameters in the Task search feature, potentially allowing unauthorized data access, modification, or system compromise.
Technical details
This is a SQL injection vulnerability (CWE-89) in the Task search functionality of Apache Syncope. The vulnerable component fails to properly sanitize sort clause parameters, allowing an authenticated administrator with sufficient entitlements to inject stacked SQL queries. The attack requires administrative privileges and network access to the application. An attacker can execute arbitrary SQL commands to read, modify, or delete data from the underlying database. Patches are available in versions 4.0.8, 4.1.3, and later.
Affected products
- Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2
Timeline
- 2026-09-14: disclosed