Sensitive Information Exposure in Apache Syncope by The Apache Software Foundation
CVE-2026-73178

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-73178?

A vulnerability exists in Apache Syncope that allows an authorized administrator to access sensitive information via REST, specifically the list of existing access tokens and their signed JWT bodies. This exposure could lead to unauthorized impersonation of users with elevated administrative privileges. Affected users are strongly advised to upgrade to versions 4.0.8 or 4.1.3 to mitigate risks associated with this vulnerability.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.