securityonline.info 7/23/2026, 4:32:16 PM · external

Apache Syncope Patches SQL Injection and Privilege Escalation Flaws

Apache Syncope Patches SQL Injection and Privilege Escalation Flaws
CyberSIXT Evidence Panel
Primary Source syncope.apache.org
CISA KEV Not in KEV
Patch Patch Status Unknown

THE Apache Software Foundation has addressed two critical vulnerabilities in Apache Syncope, identified as CVE-2026-57308 (SQL injection) and CVE-2026-62183 (privilege escalation), both with a severity rating of 9.8 (Critical · CVSSv3). There is no confirmed public exploitation of these vulnerabilities yet, but they pose significant risks as they can allow unauthorized access to administrator privileges. The vulnerabilities affect versions 3.0.0-M0 to 4.1.1 and have been patched in versions 4.0.7 and 4.1.2.

Organizations are advised to update immediately and review self-service workflow configurations to avoid potential exploitation.

View Primary Source Via securityonline.info

Article by CyberSIXT