Insufficiently Protected Credentials Vulnerability in Apache Syncope by Apache
CVE-2026-75015
Currently unrated
What is CVE-2026-75015?
The vulnerability in Apache Syncope is related to insufficient protection of sensitive credentials during audit events. Specifically, when audit events are sent to the configured store, they fail to sufficiently mask sensitive values contained within their payloads. This lack of masking allows administrators to access potentially confidential information, posing a significant security risk. Users are encouraged to upgrade to versions 4.0.8 or 4.1.3, which address this vulnerability and enhance the protection of sensitive data.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2