Incorrect Authorization in Apache Syncope Affects User Security
CVE-2026-73236

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-73236?

An incorrect authorization vulnerability exists in Apache Syncope, attributed to improper security checks related to Realm hierarchy. The flaw arises when two sibling Realms, sharing the same name prefix, are inaccurately handled, leading to potential unauthorized access. This issue is present in multiple versions of Apache Syncope, necessitating prompt updates to preserve the integrity of user access control. Users are advised to upgrade to versions 4.0.8 or 4.1.3 to mitigate this risk.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aleksandar Djordjevic
n0mi1k
.