SQL injection in Apache Syncope - CVE-2026-77051
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary SQL commands.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in the Audit Events search functionality when processing unsanitized entityKey and opEvent parameters. A remote privileged user can submit crafted parameter values to execute arbitrary SQL commands.