High severity8.1NVD Advisory· Published Jul 20, 2026· Updated Jul 27, 2026
CVE-2026-62418
CVE-2026-62418
Description
Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
Affected products
2Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/07/20/10nvdMailing ListThird Party Advisory
- lists.apache.org/thread/n632drbsmfr6t3p6jt6jwbjvokqdyszbnvdMailing ListVendor Advisory
News mentions
1- Apache Syncope Release Patches for Multiple RCE and SQL Injection VulnerabilitiesCyber Security News · Jul 24, 2026