Apache Syncope admin-level SQL injection
SQL injection in Apache Syncope allows an administrator with adequate entitlements to execute arbitrary SQL commands against the configured relational database backend.
- Vendor
- Apache
- Product
- Syncope
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.6%
- Status
- patched
- Published
Apache Syncope contains a SQL injection path accessible to administrators holding adequate entitlements. An administrator exploiting this flaw can execute arbitrary SQL statements against the underlying relational database.
The access requirement is higher than the unauthenticated or low-privilege injection paths in the same patch batch (see CVE-2026-73579). However, admin-level SQL execution in an identity governance platform puts the full credential store at risk.
Patch via the Apache Software Foundation advisory. See the full Syncope patch article for patch priority order across all seven CVEs.
