SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-86460

CRITICAL · CVSS 9.8

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A cypher injection vulnerability exists in the Neo4j persistence layer of Apache Syncope, affecting versions from 3.0.0-M0 to 4.1.2, which could allow attackers to manipulate queries through crafted FIQL search conditions. This could potentially lead to unauthorized data access or manipulation, making it critical for organizations using affected versions to prioritize upgrading to versions 4.0.8 or 4.1.3 to mitigate the risk. Users of Apache Syncope should take immediate action to secure their installations against this vulnerability.

CVE
CVE-2026-86460
Severity
CRITICAL
CVSS
9.8
EPSS
N/A
Apache

Original NVD Description

Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.