Back

CRITICAL

Apache Syncope: ClientApp update entitlement not effective

Published Sep 14, 2026

Description

Incorrect Authorization vulnerability in Apache Syncope.

An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update operations on ClientApp.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 14, 2026
Updated Sep 14, 2026
Reserved Aug 20, 2026
CISA Vulnrichment
Updated Sep 14, 2026
NVD
Status Deferred
Modified Sep 14, 2026
Red Hat
Severity n/a
Public date n/a