Authorization Bypass Vulnerability in Apache Syncope Software
CVE-2026-75030
Currently unrated
What is CVE-2026-75030?
A missing authorization vulnerability exists in Apache Syncope, which allows administrators with task execution entitlements to mass (de)provision group members without proper group-related permissions. This flaw potentially exposes sensitive user management functions to unauthorized administrators, leading to security risks. It is crucial for users operating versions from 3.0.0-M0 to 4.1.2 to upgrade to at least version 4.0.8 or 4.1.3 to mitigate this issue.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2