CVE-2026-73668
- EPSS 0.48%
- Veröffentlicht 14.09.2026 12:51:46
- Zuletzt bearbeitet 14.09.2026 20:58:48
Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another Realm and th...
CVE-2026-77147
- EPSS 0.28%
- Veröffentlicht 14.09.2026 12:49:41
- Zuletzt bearbeitet 14.09.2026 20:58:48
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their CommandArgs sta...
CVE-2026-77181
- EPSS 0.48%
- Veröffentlicht 14.09.2026 12:48:01
- Zuletzt bearbeitet 14.09.2026 20:58:48
Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update operations on Clie...
CVE-2026-77883
- EPSS 0.38%
- Veröffentlicht 14.09.2026 12:30:53
- Zuletzt bearbeitet 14.09.2026 20:58:48
Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlement...
CVE-2026-78318
- EPSS 0.25%
- Veröffentlicht 14.09.2026 12:29:34
- Zuletzt bearbeitet 14.09.2026 20:58:48
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HTML tags with ...
CVE-2026-78330
- EPSS 0.6%
- Veröffentlicht 14.09.2026 12:24:56
- Zuletzt bearbeitet 14.09.2026 20:58:48
Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authen...
CVE-2026-78336
- EPSS 0.41%
- Veröffentlicht 14.09.2026 12:23:51
- Zuletzt bearbeitet 14.09.2026 20:58:48
Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configurati...
CVE-2026-82232
- EPSS 0.56%
- Veröffentlicht 14.09.2026 10:45:44
- Zuletzt bearbeitet 14.09.2026 20:58:48
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized so...
CVE-2026-86460
- EPSS 0.56%
- Veröffentlicht 14.09.2026 10:43:58
- Zuletzt bearbeitet 14.09.2026 20:58:48
Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are reco...
CVE-2026-87779
- EPSS 0.41%
- Veröffentlicht 14.09.2026 10:42:56
- Zuletzt bearbeitet 14.09.2026 20:58:48
Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The resulting key value is logged...