Description
Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions.



This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.



Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Cypher injection allowing arbitrary Cypher command execution within the application.
Action: Patch Immediately
AI Analysis

Impact

This vulnerability is a Cypher injection flaw in the Neo4j persistence layer of Apache Syncope. The flaw is triggered by certain FIQL search conditions that are not properly sanitized. An attacker who can supply a crafted FIQL query could inject and execute arbitrary Cypher statements, potentially reading, modifying, or deleting data stored in Neo4j. The weakness aligns with CWE‑89, which governs injection attacks that enable execution of unintended commands.

Affected Systems

Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are affected. Upgrade to 4.0.8 or 4.1.3 eliminates the vulnerability.

Risk and Exploitability

The CVSS score indicates a high severity of 9.8, while the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote API or web endpoint that accepts FIQL search parameters, allowing an unauthenticated or authenticated attacker to inject malicious Cypher statements if they can submit the query. Because the injection can execute arbitrary Cypher, the impact may be total loss of data confidentiality, integrity, and availability. The low EPSS score suggests exploitation is not yet widespread, but the high CVSS score warrants immediate attention, especially if the FIQL endpoint is exposed.

Generated by OpenCVE AI on September 21, 2026 at 00:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading Apache Syncope to version 4.0.8 or 4.1.3.
  • Restrict or disable FIQL search functionality for untrusted users, or enforce strict input validation to prevent the construction of malicious Cypher queries.
  • Ensure Neo4j is operated with strong authentication and network access controls, limiting the ability of external actors to influence query construction.

Generated by OpenCVE AI on September 21, 2026 at 00:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope

Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
Weaknesses CWE-89
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:47:16.698Z

Reserved: 2026-09-07T13:21:35.376Z

Link: CVE-2026-86460

cve-icon Vulnrichment

Updated: 2026-09-14T18:09:22.402Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:05.250

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-86460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')