Insufficiently Protected Credentials Vulnerability in Apache Syncope by Apache
CVE-2026-75015

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-75015?

The vulnerability in Apache Syncope is related to insufficient protection of sensitive credentials during audit events. Specifically, when audit events are sent to the configured store, they fail to sufficiently mask sensitive values contained within their payloads. This lack of masking allows administrators to access potentially confidential information, posing a significant security risk. Users are encouraged to upgrade to versions 4.0.8 or 4.1.3, which address this vulnerability and enhance the protection of sensitive data.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.