Apache Syncope

22 known vulnerabilities in Apache Syncope, 12 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-73370 CVSS 9.8 critical Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconciliation service's…
  • CVE-2026-73236 CVSS 7.5 high Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm hierarchy and…
  • CVE-2026-73195 CVSS 7.3 high Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet formula payload in…
  • CVE-2026-73191 CVSS 6.1 medium URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS…
  • CVE-2026-78336 CVSS 7.5 high Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of…
  • CVE-2026-78330 CVSS 9.8 critical Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are…
  • CVE-2026-78318 CVSS 6.1 medium Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification…
  • CVE-2026-77883 CVSS 4.9 medium Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for…
  • CVE-2026-77181 CVSS 9.8 critical Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the…
  • CVE-2026-77147 CVSS 6.5 medium Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for…
  • CVE-2026-77051 CVSS 9.8 critical Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator…
  • CVE-2026-75030 CVSS 9.8 critical Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass…
  • CVE-2026-75015 CVSS 4.9 medium Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not…
  • CVE-2026-73668 CVSS 9.8 critical Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read…
  • CVE-2026-73579 CVSS 9.8 critical Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch…
  • CVE-2026-73470 CVSS 9.8 critical Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the…
  • CVE-2026-73178 CVSS 7.5 high Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements…
  • CVE-2026-87802 CVSS 9.1 critical Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set…
  • CVE-2026-87785 CVSS 9.1 critical Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are…
  • CVE-2026-87779 CVSS 7.5 high Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes)…
  • CVE-2026-86460 CVSS 9.8 critical Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache…
  • CVE-2026-82232 CVSS 9.8 critical Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator…