Improper Cryptographic Signature Verification in Apache Syncope
CVE-2026-87802

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-87802?

An improper verification of cryptographic signature vulnerability exists in Apache Syncope that allows attackers to forge arbitrary JSON Web Tokens (JWTs) when Single Resource Access (SRA) is configured for OAuth 2.0 without a assigned JWKS set URI. By exploiting this flaw, an attacker can impersonate any user identity and permissions, potentially gaining unauthorized access to various services proxied by the SRA. It is recommended for users to update to Apache Syncope versions 4.0.8 or 4.1.3 to mitigate this security risk.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MopMonk AI
.