Executive brief
Apache Syncope is an open-source identity and access management platform that uses a Neo4j graph database for persistence. A Cypher injection vulnerability in the FIQL search condition processor allows attackers to inject malicious database queries, potentially leading to unauthorized data access, modification, or deletion of identity records and configurations. This could compromise the entire identity management infrastructure and expose sensitive user and system data.
Technical details
The vulnerability is a Cypher injection flaw in the Neo4j persistence layer when processing FIQL (Feed Item Query Language) search conditions. The affected code fails to properly sanitize user input before constructing Cypher queries, allowing an attacker to inject arbitrary Cypher code. The vulnerability is exploitable over the network without authentication requirements for affected FIQL endpoints. An attacker can leverage this to execute arbitrary Cypher queries against the Neo4j database, potentially exfiltrating sensitive data, modifying identity records, or disrupting service availability. Patches are available in versions 4.0.8 and 4.1.3; users on 3.x branches should upgrade to the latest available 3.0.x version.
Affected products
- Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2
Timeline
- 2026-09-14: disclosed