org.apache.syncope.core:syncope-core-persistence-jpa vulnerabilities
CVEs whose affected-version data names the org.apache.syncope.core:syncope-core-persistence-jpa package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-82232Critical· 9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging u…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging u…
▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-jpaEPSS 0.56%via NVD
CVE-2026-77051Critical· 9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging…
▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-jpaEPSS 0.56%via NVD