Incorrect Privilege Assignment Vulnerability in Apache Syncope
CVE-2026-78330
Currently unrated
What is CVE-2026-78330?
This vulnerability arises from incorrect privilege assignment within Apache Syncope. Specifically, when JWKS settings for internal JWT authentication are improperly disclosed, an attacker can exploit this information to gain administrative privileges. After successfully authenticating and obtaining a valid low-privilege JWT, the attacker can execute actions that should be reserved for administrators. To mitigate this risk, users are strongly encouraged to upgrade to Apache Syncope version 4.0.8 or 4.1.3, which address this vulnerability.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2