CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-57308

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
0.38%
30th pct
KEV
No
Class
other
CWE-89

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.

References

Status: profiled · ingested 2026-07-27T18:00:00.000Z