Authentication Bypass Vulnerability in Apache Syncope by Apache
CVE-2026-87785
Currently unrated
What is CVE-2026-87785?
This vulnerability allows attackers to spoof user privileges by disclosing the configured JWKS settings for internal JWT authentication. After successfully authenticating and obtaining a valid JWT, malicious actors can exploit this flaw to impersonate other users, potentially compromising sensitive data and system integrity. It affects specific versions of Apache Syncope, making immediate upgrades to versions 4.0.8 or 4.1.3 essential for ensuring security.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2