https://seclists.org/oss-sec/2026/q3/771: CVE-2026-82232: Apache Syncope: SQL injection via sort parameter in Task search
Published Sep 14, 2026
·Updated
Affected Software
3 affected components
Apache Syncope>=3.0.0-M0<=3.0.16
Apache Syncope>=4.0.0-M0<=4.0.7
Apache Syncope>=4.1.0-M0<=4.1.2
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires an administrator account with adequate entitlements. The attacker must be able to leverage the Task search functionality and supply unsanitized sort clauses.
2
Which deployments are affected?
Affected persistence JPA component versions are 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2.
3
What should be done to remediate the issue?
Upgrade to Apache Syncope version 4.0.8 or 4.1.3, which contain the fix.