Known Vulnerabilities for Syncope by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Syncope" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63071 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for ... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-62418 json | Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-62183 json | Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-57308 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An adm... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-53421 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements ca... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-53405 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can ... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-42797 json | Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entit... | Not Provided | 2026-05-25 | 2026-05-26 |
| CVE-2026-42782 json | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for ... | Not Provided | 2026-05-25 | 2026-05-27 |
| CVE-2020-11977 json | In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entit... | 7.2 - HIGH | 2020-09-15 | 2020-09-24 |
| CVE-2020-1961 json | Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X re... | 9.8 - CRITICAL | 2020-05-04 | 2020-05-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Syncope | 2.1.7 | |||
| Application | Apache | Syncope | 2.1.6 | |||
| Application | Apache | Syncope | 2.1.5 | |||
| Application | Apache | Syncope | 2.1.4 | |||
| Application | Apache | Syncope | 2.1.3 | |||
| Application | Apache | Syncope | 2.1.2 | |||
| Application | Apache | Syncope | 2.1.1 | |||
| Application | Apache | Syncope | 2.1.0 | |||
| Application | Apache | Syncope | 2.0.9 | |||
| Application | Apache | Syncope | 2.0.8 | |||
| Application | Apache | Syncope | 2.0.7 | |||
| Application | Apache | Syncope | 2.0.6 | |||
| Application | Apache | Syncope | 2.0.5 | |||
| Application | Apache | Syncope | 2.0.4 | |||
| Application | Apache | Syncope | 2.0.3 | |||
| Application | Apache | Syncope | 2.0.2 | |||
| Application | Apache | Syncope | 2.0.15 | |||
| Application | Apache | Syncope | 2.0.14 | |||
| Application | Apache | Syncope | 2.0.13 | |||
| Application | Apache | Syncope | 2.0.12 |