Apache Syncope: SRA OAuth2 JWT signature verification bypass
Published Sep 14, 2026
9.1
CRITICALCVSS 3.1
EPSS 0.28%
Description
Improper verification of cryptographic signature vulnerability in Apache Syncope.
When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected products
-
- Version 3.0.0-M0StatusaffectedConstraints<=3.0.16
- Version 4.0.0-M0StatusaffectedConstraints<=4.0.7
- Version 4.1.0-M0StatusaffectedConstraints<=4.1.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Syncope | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- http://www.openwall.com/lists/oss-security/2026/09/14/25
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77358 Advisory
- https://lists.apache.org/thread/gx83cootj00kn8hqd73x1bp8441np33d vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/14/25 | ||
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77358 | Advisory | |
| https://lists.apache.org/thread/gx83cootj00kn8hqd73x1bp8441np33d | vendor-advisory |
Change history (0)
No recorded changes yet.