Apache Syncope

Apache · 40 CVEs

CVE-2026-73191
MEDIUM

Apache Syncope: CAS service URL injection via Forwarded HTTP headers

Sep 14, 2026

CVE-2026-73195
HIGH

Apache Syncope: CSV export spreadsheet formula injection

Sep 14, 2026

CVE-2026-73236
HIGH

Apache Syncope: Cross-Realm authorization bypass in delegated administration

Sep 14, 2026

CVE-2026-73370
CRITICAL

Apache Syncope: Cross-Realm boundaries reconciliation bypass

Sep 14, 2026

CVE-2026-73178
HIGH

Apache Syncope: JWT Access Token takeover

Sep 14, 2026

CVE-2026-73470
CRITICAL

Apache Syncope: Delegating users can grant unowned Roles

Sep 14, 2026

CVE-2026-73579
CRITICAL

Apache Syncope: Non-recursive Any search could skip Realms restrictions

Sep 14, 2026

CVE-2026-75015
MEDIUM

Apache Syncope: Nested secrets leak cleartext into audit records readable

Sep 14, 2026

CVE-2026-75030
CRITICAL

Apache Syncope: Incomplete authorization checks for Group members deprovisioning

Sep 14, 2026

CVE-2026-77051
CRITICAL

Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search

Sep 14, 2026

CVE-2026-73668
CRITICAL

Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values

Sep 14, 2026

CVE-2026-77147
MEDIUM

Apache Syncope: Groovy Sandbox escape for empty CommandArgs

Sep 14, 2026

CVE-2026-77181
CRITICAL

Apache Syncope: ClientApp update entitlement not effective

Sep 14, 2026

CVE-2026-77883
MEDIUM

Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist

Sep 14, 2026

CVE-2026-78318
MEDIUM

Apache Syncope: Unauthenticated reflected XSS in Console and Enduser

Sep 14, 2026

CVE-2026-78330
CRITICAL

Apache Syncope: Privilege escalation for admin user via JWT authentication

Sep 14, 2026

CVE-2026-78336
HIGH

Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user

Sep 14, 2026

CVE-2026-82232
CRITICAL

Apache Syncope: SQL injection via sort parameter in Task search

Sep 14, 2026

CVE-2026-86460
CRITICAL

Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence

Sep 14, 2026

CVE-2026-87779
HIGH

Apache Syncope: AES Secret Key disclosure via log output

Sep 14, 2026

CVE-2026-87785
CRITICAL

Apache Syncope: JWT subject spoofing

Sep 14, 2026

CVE-2026-87802
CRITICAL

Apache Syncope: SRA OAuth2 JWT signature verification bypass

Sep 14, 2026

CVE-2026-62418
HIGH

Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check

Jul 20, 2026

CVE-2026-62183
CRITICAL

Apache Syncope: User self-service privilege escalation

Jul 20, 2026

CVE-2026-57308
CRITICAL

Apache Syncope: SQL injection vulnerability in Audit Events search

Jul 20, 2026

Showing 1 to 25 of 40 CVEs