Authorization Flaw in Apache Syncope Affects User Permissions
CVE-2026-73579

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-73579?

An incorrect authorization vulnerability in Apache Syncope allows unauthorized access due to an ineffective Realms filter. This security lapse can permit users to bypass intended access controls when non-recursive search requests result in an empty filter. Users are urged to update their installations to versions 4.0.8 or 4.1.3 to mitigate this issue and ensure proper permission restrictions.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.