Server-Side Request Forgery Vulnerability in Apache Syncope
CVE-2026-62418

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
20 July 2026

What is CVE-2026-62418?

A low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability exists in Apache Syncope. This vulnerability impacts the handling of Connectors and Resources, allowing potentially malicious requests to be made by authenticated users. The affected versions range from 3.0.0-M0 to 3.0.16, 4.0.0-M0 to 4.0.6, and 4.1.0-M0 to 4.1.1. It is highly recommended for users to upgrade to versions 4.0.7 or 4.1.2 to mitigate this issue.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.6

Apache Syncope 4.1.0-M0 <= 4.1.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrián Leal Castaño
.