Server-Side Request Forgery Vulnerability in Apache Syncope
CVE-2026-62418
Currently unrated
What is CVE-2026-62418?
A low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability exists in Apache Syncope. This vulnerability impacts the handling of Connectors and Resources, allowing potentially malicious requests to be made by authenticated users. The affected versions range from 3.0.0-M0 to 3.0.16, 4.0.0-M0 to 4.0.6, and 4.1.0-M0 to 4.1.1. It is highly recommended for users to upgrade to versions 4.0.7 or 4.1.2 to mitigate this issue.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.6
Apache Syncope 4.1.0-M0 <= 4.1.1