Sensitive Information Exposure in Apache Syncope by The Apache Software Foundation
CVE-2026-73178
Currently unrated
What is CVE-2026-73178?
A vulnerability exists in Apache Syncope that allows an authorized administrator to access sensitive information via REST, specifically the list of existing access tokens and their signed JWT bodies. This exposure could lead to unauthorized impersonation of users with elevated administrative privileges. Affected users are strongly advised to upgrade to versions 4.0.8 or 4.1.3 to mitigate risks associated with this vulnerability.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2