Information Exposure Vulnerability in Apache Syncope
CVE-2026-77883

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-77883?

A vulnerability has been identified in Apache Syncope that allows an administrator with the right privileges to create a malicious JEXL expression. This expression can expose sensitive information from LinkedAccount or Manager entities, potentially including hashed credentials. It is crucial for users to upgrade to the latest versions (4.0.8 / 4.1.3) to mitigate the risk posed by this vulnerability.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.