Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 11:17
Updated : 2026-09-14 20:58
NVD link : CVE-2026-86460
Mitre link : CVE-2026-86460
CVE.ORG link : CVE-2026-86460
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
