Apache syncope
This hub aggregates every CVE we track for Apache syncope, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
18
CVEs tracked
5
Critical
6
High
0
In CISA KEV
Severity distribution
MEDIUM7HIGH6CRITICAL5
Monthly trend
0
1
0
0
0
0
0
0
0
0
0
0
0
1
1
0
0
2
0
0
2
0
6
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache syncope.
- CVE-2026-62418Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check8.1
- CVE-2026-62183Apache Syncope: User self-service privilege escalation9.8
- CVE-2026-57308Apache Syncope: SQL injection vulnerability in Audit Events search9.8
- CVE-2026-53421Apache Syncope: Remote Code Execution via Scripted Connector9.8
- CVE-2026-53405Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask9.8
- CVE-2026-63071Apache Syncope: RCE via Groovy Sandbox bypass9.8
- CVE-2026-42797Apache Syncope: JexlContextBuilder Information Disclosure4.9
- CVE-2026-42782Apache Syncope: Post-auth RCE via Groovy static7.2
- CVE-2026-23794Apache Syncope: Reflected XSS on Enduser Login6.8
- CVE-2026-23795Apache Syncope: Console XXE on Keymaster parameters4.9
- CVE-2025-65998Apache Syncope: Default AES key used for internal password encryption7.5
- CVE-2025-57738Apache Syncope: Remote Code Execution by delegated administrators7.2
- CVE-2024-45031Apache Syncope: Stored XSS in Console and Enduser6.1
- CVE-2024-38503Apache Syncope: HTML tags can be injected into Console or Enduser text fields5.4
- CVE-2018-17186An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.7.2
Product normalization is registry-driven with AI assist and human review. How it works