Authorization Flaw in Apache Syncope Affects User Permissions
CVE-2026-73579
Currently unrated
What is CVE-2026-73579?
An incorrect authorization vulnerability in Apache Syncope allows unauthorized access due to an ineffective Realms filter. This security lapse can permit users to bypass intended access controls when non-recursive search requests result in an empty filter. Users are urged to update their installations to versions 4.0.8 or 4.1.3 to mitigate this issue and ensure proper permission restrictions.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2