securityonline.info 16 Sept 2026, 01:50 UTC

Apache Syncope Fixes Six Flaws, Including Critical SQL Injection and Sandbox Escape

Apache Syncope Fixes Six Flaws, Including Critical SQL Injection and Sandbox Escape

THE Apache Software Foundation has released fixes for six vulnerabilities in Apache Syncope, an open-source identity-management platform. The flaws affect the 3.0, 4.0 and 4.1 branches: versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. The issues are rated as two critical, three high and one medium, with CVE-2026-82232 and CVE-2026-73470 each receiving a CVSS v3 score of 9.8. No active exploitation has been confirmed.

The most serious issue, CVE-2026-82232, allows an administrator with sufficient entitlements to execute arbitrary SQL through stacked queries by exploiting unsanitised sort clauses in task searches. CVE-2026-77147 permits an administrator to create a malicious Groovy class that escapes the security sandbox.

Other flaws can expose active JWT access tokens (CVE-2026-73178), disclose an AES secret key through log output (CVE-2026-87779), enable cross-realm authorisation bypasses in delegated administration (CVE-2026-73236), or let delegated users grant roles they do not own (CVE-2026-73470).

The vulnerabilities are fixed in Apache Syncope 4.0.8 and 4.1.3. The article says there are no practical workarounds, so administrators should upgrade to a fixed release using the official Apache Syncope downloads.

View full article

Article by CyberSIXT