THE Apache Software Foundation has released fixes for six vulnerabilities in Apache Syncope, an open-source identity-management platform. The flaws affect the 3.0, 4.0 and 4.1 branches: versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. The issues are rated as two critical, three high and one medium, with CVE-2026-82232 and CVE-2026-73470 each receiving a CVSS v3 score of 9.8. No active exploitation has been confirmed.
The most serious issue, CVE-2026-82232, allows an administrator with sufficient entitlements to execute arbitrary SQL through stacked queries by exploiting unsanitised sort clauses in task searches. CVE-2026-77147 permits an administrator to create a malicious Groovy class that escapes the security sandbox.
Other flaws can expose active JWT access tokens (CVE-2026-73178), disclose an AES secret key through log output (CVE-2026-87779), enable cross-realm authorisation bypasses in delegated administration (CVE-2026-73236), or let delegated users grant roles they do not own (CVE-2026-73470).
The vulnerabilities are fixed in Apache Syncope 4.0.8 and 4.1.3. The article says there are no practical workarounds, so administrators should upgrade to a fixed release using the official Apache Syncope downloads.