CVE-2026-57308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
References
Link Resource
https://lists.apache.org/thread/g0gpctj90pbczbjl5jr33t8gr1gltg8v Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/07/20/8 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*

History

27 Jul 2026, 15:00

Type Values Removed Values Added
First Time Apache
Apache syncope
CPE cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
References () https://lists.apache.org/thread/g0gpctj90pbczbjl5jr33t8gr1gltg8v - () https://lists.apache.org/thread/g0gpctj90pbczbjl5jr33t8gr1gltg8v - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/07/20/8 - () http://www.openwall.com/lists/oss-security/2026/07/20/8 - Mailing List, Third Party Advisory

21 Jul 2026, 16:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

20 Jul 2026, 19:17

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/07/20/8 -

20 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 15:16

Updated : 2026-07-27 15:00


NVD link : CVE-2026-57308

Mitre link : CVE-2026-57308

CVE.ORG link : CVE-2026-57308


JSON object : View

Products Affected

apache

  • syncope
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')