CVE-2026-57308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
References
Link Resource
https://lists.apache.org/thread/g0gpctj90pbczbjl5jr33t8gr1gltg8v Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/07/20/8 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-20 15:16

Updated : 2026-07-27 15:00


NVD link : CVE-2026-57308

Mitre link : CVE-2026-57308

CVE.ORG link : CVE-2026-57308


JSON object : View

Products Affected

apache

  • syncope
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')