Sensitive Information Exposure in Apache Syncope by Apache
CVE-2026-78336
Currently unrated
What is CVE-2026-78336?
An issue has been identified in Apache Syncope that allows authenticated users to retrieve a list of configured OIDC providers for Single Sign-On (SSO). This retrieval exposes sensitive configuration data, including client secrets, in the response payload without regard to user entitlements. It is crucial for users running affected versions to upgrade to 4.0.8 or 4.1.3 to mitigate this security risk.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2