4.9

CVE-2026-42797

Apache Syncope: JexlContextBuilder Information Disclosure

Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.

An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information.

This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.

Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Syncope Version >= 3.0.0 <= 3.0.16
Apache ≫ Syncope Version >= 4.0.0 < 4.0.6
Apache ≫ Syncope Version 4.1.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.357
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-202 Exposure of Sensitive Information Through Data Queries

When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

https://lists.apache.org/thread/5y7d277sntyytrmxnx2tfjr9ftcpq1s6
Vendor Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/25/5
Third Party Advisory
Mailing List