
Apache Syncope Flaws Enable SQL Injection, JWT Token Takeover and Code Injection
Apache Syncope has disclosed three important vulnerabilities that could allow privileged administrators to execute arbitrary SQL commands, bypass Groovy sandbox protections to inject code, and hijack higher-privileged user sessions through exposed JWT access tokens. Tracked as CVE-2026-82232, CVE-2026-77147, and CVE-2026-73178, the flaws affect multiple Apache Syncope 3.0, 4.0, and 4.1 releases. Organizations using affected instances […]
The post Apache Syncope Flaws Enable SQL Injection, JWT Token Takeover and Code Injection appeared first on Cyber Security News.