Vulnerability intelligence
CVE-2026-57308
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.4%
Riskier than 30% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jul 23, 2026 · latest Jul 23, 2026
Coverage timeline
-
Apache Syncope Patches SQL Injection and Privilege Escalation Flawssecurityonline.info · Jul 23, 2026