Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-86460: Apache Syncope search can run unintended database commands
CVE-2026-86460 · published 11 days ago
Summary
Apache Syncope versions from 3.0.0-M0 up to 4.1.2 may allow specially crafted search queries to execute extra commands in its Neo4j database. This could let an attacker read, change, or delete data stored by the system. Upgrade to version 4.0.8 or 4.1.3, which contain the fix.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache syncope | <= 3.0.16 |
Original advisory text
Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through ...
Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published14 Sep 2026
Updated25 Sep 2026
First seen14 Sep 2026
Track software like this
Free during beta