Open Redirect Vulnerability in Apache Syncope Affects Multiple Versions
CVE-2026-73191

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-73191?

An open redirect vulnerability exists in Apache Syncope when configured for CAS authentication. The vulnerability arises from the application's reliance on unconditionally using client-supplied forwarded HTTP headers to determine the URL for the Apereo CAS instance. This can lead to the potential for redirection to untrusted sites, increasing the risk of phishing attacks and unauthorized access. Users are urged to upgrade to versions 4.0.8 or 4.1.3 to mitigate this risk.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meifukun
.