Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.





An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized entityKey and opEvent parameters.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.


Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

An administrator with sufficient privileges can cause an unfiltered SQL query to be executed by the Apache Syncope application. The flaw originates from unsanitized entityKey and opEvent parameters that are used in the Audit Events search functionality, enabling an attacker to inject arbitrary SQL statements. This can lead to data disclosure, manipulation of database contents, or further exploitation of the underlying database. The vulnerability is categorized as CWE-89, a classic SQL injection weakness.

Affected Systems

The flaw exists in Apache Syncope versions from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2. The vendor is Apache Software Foundation’s Apache Syncope. Users of these versions should upgrade to at least 4.0.8 or 4.1.3 to apply the fix.

Risk and Exploitability

The CVSS score of 9.8 indicates high severity. The vulnerability requires an attacker to have access to an account with administrator privileges, therefore the attack surface is limited to insiders or compromised credential scenarios. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. However, the nature of the flaw allows execution of stacked queries, which could provide attackers with significant data manipulation or exfiltration capabilities.

Generated by OpenCVE AI on September 21, 2026 at 00:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to version 4.0.8 or 4.1.3, which addresses the SQL injection issue.
  • Ensure that only trusted administrators have access to the Audit Events search endpoint, and enforce strict role‑based access control.
  • Validate and sanitize the entityKey and opEvent input parameters on all request paths before they are incorporated into SQL queries.

Generated by OpenCVE AI on September 21, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized entityKey and opEvent parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search
Weaknesses CWE-89
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:25:08.227Z

Reserved: 2026-08-20T09:33:19.366Z

Link: CVE-2026-77051

cve-icon Vulnrichment

Updated: 2026-09-14T18:09:12.142Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:18:46.363

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-77051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T07:15:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')