CRITICAL
9.8 CVE-2026-82232 Published 14 Sept 2026
Apache Syncope SQL Injection Vulnerability
Worried this affects one of your servers?
Apache Syncope, a popular identity management platform, is affected by an SQL injection vulnerability.
Syncope allows an administrator with sufficient privileges to execute arbitrary SQL queries by exploiting unsanitized sort clauses in the Task search feature.
This issue affects Syncope versions from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2.
Users are advised to upgrade to version 4.0.8 or 4.1.3 to mitigate this vulnerability.
Reference: CVE-2026-82232 on NVD
← Back to Security News