Apache Syncope Vulnerabilities Allow Attackers to Execute Malicious Code and Bypass Controls
ID: 2cc0bc01-1cbc-557e-ba8d-07f6c31093d5
STIX ID: report--2cc0bc01-1cbc-557e-ba8d-07f6c31093d5
Feed Name: cybersecurityNews.com
Apache Syncope disclosed three security flaws affecting multiple 3.x and 4.x releases — an SQL injection in Task search (CVE-2026-82232) that can support stacked queries, a Groovy sandbox escape via malicious CommandArgs (CVE-2026-77147), and a JWT access-token takeover (CVE-2026-73178). These issues could expose, modify, or allow impersonation over identity data and administrative functions; fixed versions are 4.0.8 and 4.1.3 and administrators are advised to upgrade, audit privileged accounts and REST activity, rotate tokens, and monitor for suspicious database and API behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
