Sensitive Information Exposure in Apache Syncope by Apache
CVE-2026-78336

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-78336?

An issue has been identified in Apache Syncope that allows authenticated users to retrieve a list of configured OIDC providers for Single Sign-On (SSO). This retrieval exposes sensitive configuration data, including client secrets, in the response payload without regard to user entitlements. It is crucial for users running affected versions to upgrade to 4.0.8 or 4.1.3 to mitigate this security risk.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Moritz Theile
.