Authentication Bypass Vulnerability in Apache Syncope by Apache
CVE-2026-87785

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-87785?

This vulnerability allows attackers to spoof user privileges by disclosing the configured JWKS settings for internal JWT authentication. After successfully authenticating and obtaining a valid JWT, malicious actors can exploit this flaw to impersonate other users, potentially compromising sensitive data and system integrity. It affects specific versions of Apache Syncope, making immediate upgrades to versions 4.0.8 or 4.1.3 essential for ensuring security.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alon Galili
.