9.1
CVE-2026-87785
- EPSS 0.51%
- Veröffentlicht 14.09.2026 10:38:12
- Zuletzt bearbeitet 14.09.2026 20:58:48
- Erkennungen
Apache Syncope: JWT subject spoofing
Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a successful authentication and obtaining a valid JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerApache Software Foundation
≫
Produkt
Apache Syncope
Default Statusunaffected
Version <=
3.0.16
Version
3.0.0-M0
Status
affected
Version <=
4.0.7
Version
4.0.0-M0
Status
affected
Version <=
4.1.2
Version
4.1.0-M0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.51% | 0.422 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-290 Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
https://lists.apache.org/thread/3t3om8mny7ng52q053pdzpmtdtosnqoo
http://www.openwall.com/lists/oss-security/2026/09/14/24