Multiple security vulnerabilities affecting Apache Syncope versions Both flaws share the same affected ranges 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1.
CVE-2026-57308 (CVSS 9.8 — Critical): This bug lives in the Audit Events search. An administrator with the right entitlements can run arbitrary SQL through stacked queries. The root cause is unsanitized sort parameters. Because it requires admin entitlements, the attacker must already hold significant access.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting Apache Syncope versions Both flaws share the same affected ranges 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1.
CVE-2026-57308 (CVSS 9.8 — Critical): This bug lives in the Audit Events search. An administrator with the right entitlements can run arbitrary SQL through stacked queries. The root cause is unsanitized sort parameters. Because it requires admin entitlements, the attacker must already hold significant access.[emaillocker id="1283"]
CVE-2026-62183 (CVSS 9.8 — Critical): This issue affects user self-service workflows. It applies when the all-Java workflow adapter is used, or a Flowable BPMN definition skips admin approval for self-registration or self-update. In that setup, a REST API call can let a user grant themselves defined roles. Consequently, they gain the entitlements tied to those roles and act as an administrator.
These vulnerabilities collectively present a significant risk to enterprise environments where Syncope manages digital identities.
We recommend you to update Apache Syncope to version 4.0.7 or 4.1.2.
The following reports contain further technical details:
[/emaillocker]