CRITICAL 9.8 CVE-2026-82232 Published 14 Sept 2026

Apache Syncope SQL Injection Vulnerability

Worried this affects one of your servers?

Apache Syncope, a popular identity management platform, is affected by an SQL injection vulnerability.

Syncope allows an administrator with sufficient privileges to execute arbitrary SQL queries by exploiting unsanitized sort clauses in the Task search feature.

This issue affects Syncope versions from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2.

Users are advised to upgrade to version 4.0.8 or 4.1.3 to mitigate this vulnerability.

Reference: CVE-2026-82232 on NVD

← Back to Security News