Incorrect Authorization in Apache Syncope Affects Multifaceted User Management
CVE-2026-73668

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-73668?

An Incorrect Authorization vulnerability in Apache Syncope allows unauthorized administrators to access full Connector configurations, including sensitive properties, from other Realms. This can lead to unauthorized duplication of Connector instances into realms where these administrators have privileges, posing risks to user data privacy. It is crucial for users to upgrade to versions 4.0.8 / 4.1.3 to mitigate this vulnerability.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.