Multiple security vulnerabilities affecting Syncope versions ** | **Fixed** | have been identified in Apache Syncope identity and access management (IAM) platform to address remote code execution (RCE), SQL injection, privilege escalation, server-side request forgery (SSRF), and information disclosure. These flaws affect various versions of Syncope, including 3.0.0-M0 to 3.0.16, 4.0.0-M0 to 4.0.6, and 4.1.0–4.1.2. Administrators are strongly urged to upgrade promptly to the latest secure releases.
CVE-2026-57308 (CVSS 9.8 — Critical): A SQL injection vulnerability affects the Audit Events search functionality, allowing authenticated administrators to input unvalidated sort parameters and lead to unauthorized SQL queries against the backing database.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting Syncope versions ** | **Fixed** | have been identified in Apache Syncope identity and access management (IAM) platform to address remote code execution (RCE), SQL injection, privilege escalation, server-side request forgery (SSRF), and information disclosure. These flaws affect various versions of Syncope, including 3.0.0-M0 to 3.0.16, 4.0.0-M0 to 4.0.6, and 4.1.0–4.1.2. Administrators are strongly urged to upgrade promptly to the latest secure releases.
CVE-2026-57308 (CVSS 9.8 — Critical): A SQL injection vulnerability affects the Audit Events search functionality, allowing authenticated administrators to input unvalidated sort parameters and lead to unauthorized SQL queries against the backing database.[emaillocker id="1283"]
CVE-2026-62183: Privilege escalation flaw in self-service workflows that allows users to assign themselves roles without proper admin approval, effectively granting them administrative access.
CVE-2026-42797 (CVSS 7.5 — High): Information disclosure bug that enables sensitive user field exposure during data reads.
CVE-2026-63071 (CVSS 9.8 — Critical): A remote code execution vulnerability can be exploited through Groovy integration and scriptable connectors, allowing attackers with adequate privileges to bypass security controls and execute untrusted code directly on the server.
CVE-2026-62418: Authenticated SSRF vulnerability that could allow crafted requests to trigger arbitrary outbound HTTP calls.
CVE-2026-53421 (CVSS 9.8 — Critical): A remote code execution vulnerability in scripted connectors can be exploited by privileged users to execute arbitrary Groovy logic, leading to post-authentication RCE.
CVE-2026-53405: Remote code execution vulnerability in Flowable Groovy that allows attackers with adequate privileges to bypass security controls and execute untrusted code directly on the server.
CVE-2026-42782: Low-privilege authenticated SSRF vulnerability that could allow crafted requests to trigger arbitrary outbound HTTP calls.
CVE-2026-23795 (CVSS 8.2 — Critical): XML External Entity (XXE) attack vulnerability in Keymaster that allows attackers to inject malicious data and potentially lead to unauthorized access or data exposure.
CVE-2026-23794: Cross-site scripting (XSS) issue in the login page that can be exploited by an attacker to steal user credentials or hijack sessions.
CVE-2025-65998: Hard-coded AES key vulnerability that allows attackers with knowledge of the key to decrypt sensitive data and potentially lead to unauthorized access or data exposure.
CVE-2025-57738 (CVSS 9.8 — Critical): Remote code execution vulnerability in Groovy implementation that can be exploited by privileged users to execute arbitrary code directly on the server.
CVE-2024-45031: Stored XSS issue in HTML sanitization that allows attackers to inject malicious data and potentially lead to unauthorized access or data exposure.
CVE-2024-38503 (CVSS 8.2 — Critical): Cross-site scripting (XSS) issue due to HTML injection vulnerability that can be exploited by an attacker to steal user credentials or hijack sessions. These vulnerabilities collectively present a significant risk to Syncope administrators and users, particularly those with access to sensitive data or systems. Administrators should upgrade promptly to the latest secure releases of Syncope to ensure ongoing security and support. These vulnerabilities collectively present a significant risk to Syncope administrators and users, particularly those with access to sensitive data or systems.
These vulnerabilities collectively present a significant risk to Syncope administrators and users, particularly those with access to sensitive data or systems.
We recommend you to update Syncope to version 4.1.2 or 4.0.7.
The following reports contain further technical details:
[/emaillocker]