Open Redirect Vulnerability in Apache Syncope Affects Multiple Versions
CVE-2026-73191
Currently unrated
What is CVE-2026-73191?
An open redirect vulnerability exists in Apache Syncope when configured for CAS authentication. The vulnerability arises from the application's reliance on unconditionally using client-supplied forwarded HTTP headers to determine the URL for the Apereo CAS instance. This can lead to the potential for redirection to untrusted sites, increasing the risk of phishing attacks and unauthorized access. Users are urged to upgrade to versions 4.0.8 or 4.1.3 to mitigate this risk.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2