Incorrect Privilege Assignment Vulnerability in Apache Syncope
CVE-2026-78330

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-78330?

This vulnerability arises from incorrect privilege assignment within Apache Syncope. Specifically, when JWKS settings for internal JWT authentication are improperly disclosed, an attacker can exploit this information to gain administrative privileges. After successfully authenticating and obtaining a valid low-privilege JWT, the attacker can execute actions that should be reserved for administrators. To mitigate this risk, users are strongly encouraged to upgrade to Apache Syncope version 4.0.8 or 4.1.3, which address this vulnerability.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Moritz Theile
.