CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit Events search
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.0.7 / 4.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57308?
CVE-2026-57308 has a critical severity rating of 9.8.
What type of vulnerability is CVE-2026-57308?
CVE-2026-57308 is an SQL injection vulnerability.
Who can exploit CVE-2026-57308?
An administrator with adequate entitlements can exploit CVE-2026-57308 due to its nature.
How can CVE-2026-57308 affect Apache Syncope?
CVE-2026-57308 can allow execution of arbitrary SQL queries through unsanitized sort parameters.
What software versions are affected by CVE-2026-57308?
CVE-2026-57308 affects specific versions of Apache Syncope, particularly those prior to the remediation of this vulnerability.