Junglewise Threat Intelligence

CVE-2026-86460: Apache Syncope Cypher injection in FIQL search conditions

CVE-2026-86460 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Vendors: Apache.

Executive brief

Apache Syncope is an open-source identity and access management platform that uses a Neo4j graph database for persistence. A Cypher injection vulnerability in the FIQL search condition processor allows attackers to inject malicious database queries, potentially leading to unauthorized data access, modification, or deletion of identity records and configurations. This could compromise the entire identity management infrastructure and expose sensitive user and system data.

Technical details

The vulnerability is a Cypher injection flaw in the Neo4j persistence layer when processing FIQL (Feed Item Query Language) search conditions. The affected code fails to properly sanitize user input before constructing Cypher queries, allowing an attacker to inject arbitrary Cypher code. The vulnerability is exploitable over the network without authentication requirements for affected FIQL endpoints. An attacker can leverage this to execute arbitrary Cypher queries against the Neo4j database, potentially exfiltrating sensitive data, modifying identity records, or disrupting service availability. Patches are available in versions 4.0.8 and 4.1.3; users on 3.x branches should upgrade to the latest available 3.0.x version.

Affected products

  • Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2

Timeline

  • 2026-09-14: disclosed

References