Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-82232

Apache Syncope admin-level SQL injection

SQL injection in Apache Syncope allows an administrator with adequate entitlements to execute arbitrary SQL commands against the configured relational database backend.

cat cve-2026-82232.json
Vendor
Apache
Product
Syncope
CVSS
9.8
EPSS (exploit probability)
0.6%
Status
patched
Published

Apache Syncope contains a SQL injection path accessible to administrators holding adequate entitlements. An administrator exploiting this flaw can execute arbitrary SQL statements against the underlying relational database.

The access requirement is higher than the unauthenticated or low-privilege injection paths in the same patch batch (see CVE-2026-73579). However, admin-level SQL execution in an identity governance platform puts the full credential store at risk.

Patch via the Apache Software Foundation advisory. See the full Syncope patch article for patch priority order across all seven CVEs.