THE Apache Software Foundation has addressed two critical vulnerabilities in Apache Syncope, identified as CVE-2026-57308 (SQL injection) and CVE-2026-62183 (privilege escalation), both with a severity rating of 9.8 (Critical · CVSSv3). There is no confirmed public exploitation of these vulnerabilities yet, but they pose significant risks as they can allow unauthorized access to administrator privileges. The vulnerabilities affect versions 3.0.0-M0 to 4.1.1 and have been patched in versions 4.0.7 and 4.1.2.
Organizations are advised to update immediately and review self-service workflow configurations to avoid potential exploitation.