SQL injection in Apache Syncope - CVE-2026-77051

 

SQL injection in Apache Syncope - CVE-2026-77051

Published: September 15, 2026


Vulnerability identifier: #VU149978
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77051
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SQL commands.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in the Audit Events search functionality when processing unsanitized entityKey and opEvent parameters. A remote privileged user can submit crafted parameter values to execute arbitrary SQL commands.


Affected software

Apache Syncope

How to mitigate CVE-2026-77051

Install security update from vendor's website.

Apache Syncope - addressed in versions 4.0.8, 4.1.3

External References

Related Security Bulletins