- Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- syncope
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@apache.org
- CWE-89
- Hype score
- Not currently trending
🚨 Apache Syncope (IAM platform) just patched multiple critical vulns: RCE via Groovy sandbox bypass, SQL injection, privilege escalation via self-role assignment, SSRF & info disclosure. CVE-2026-63071 & CVE-2026-53421 – RCE (Groovy sandbox bypass) CVE-2026-57308
@techepages
24 Jul 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ID管理OSSのApache Syncopeで、複数の遠隔コード実行(CVE-2026-63071ほか)と1件の権限昇格(CVE-2026-62183)、他SSRF (CVE-2026-62418)やSQLインジェクション(CVE-2026-57308)等の脆弱性が修正。蓄積型XSSのCVE-2018-17184といった古い脆
@__kokumoto
24 Jul 2026
631 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ID管理OSSのApacheで、複数の遠隔コード実行(CVE-2026-63071ほか)と1件の権限昇格(CVE-2026-62183)、他SSRF (CVE-2026-62418)やSQLインジェクション(CVE-2026-57308)等の脆弱性が修正。蓄積型XSSのCVE-2018-17184といった古い脆弱性も
@__kokumoto
24 Jul 2026
347 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
1 Quote
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*",
"matchCriteriaId": "81A43F1F-85A5-405B-B28A-CA2AE38D5454",
"versionEndIncluding": "3.0.16",
"versionStartIncluding": "3.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*",
"matchCriteriaId": "02A0BB79-9446-40A4-B03C-2316741BB78F",
"versionEndExcluding": "4.0.7",
"versionStartIncluding": "4.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*",
"matchCriteriaId": "000C1E11-62E0-4321-8648-BB7513E8E318",
"versionEndExcluding": "4.1.2",
"versionStartIncluding": "4.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]