https://seclists.org/oss-sec/2026/q3/772: CVE-2026-86460: Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
Published Sep 14, 2026
·Updated
Affected Software
3 affected components
Apache Syncope>=3.0.0-M0<=3.0.16
Apache Syncope>=4.0.0-M0<=4.0.7
Apache Syncope>=4.1.0-M0<=4.1.2
Frequently Asked Questions
1
Which deployments are affected?
The issue affects Apache Syncope deployments using the syncope-core-persistence-neo4j artifact: versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2.
2
What input is involved in exploitation?
The vulnerability is triggered when the Neo4j persistence layer processes certain FIQL search conditions. The provided information does not identify a specific endpoint, privilege level, or configuration prerequisite.
3
What version should affected users upgrade to?
Users should upgrade to Apache Syncope version 4.0.8 or 4.1.3, which fix the issue.