Authorization Bypass Vulnerability in Apache Syncope Software
CVE-2026-75030

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-75030?

A missing authorization vulnerability exists in Apache Syncope, which allows administrators with task execution entitlements to mass (de)provision group members without proper group-related permissions. This flaw potentially exposes sensitive user management functions to unauthorized administrators, leading to security risks. It is crucial for users operating versions from 3.0.0-M0 to 4.1.2 to upgrade to at least version 4.0.8 or 4.1.3 to mitigate this issue.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.