Apache Syncope
Apache · 40 CVEs
Apache Syncope: CAS service URL injection via Forwarded HTTP headers
Sep 14, 2026
Apache Syncope: CSV export spreadsheet formula injection
Sep 14, 2026
Apache Syncope: Cross-Realm authorization bypass in delegated administration
Sep 14, 2026
Apache Syncope: Cross-Realm boundaries reconciliation bypass
Sep 14, 2026
Apache Syncope: JWT Access Token takeover
Sep 14, 2026
Apache Syncope: Delegating users can grant unowned Roles
Sep 14, 2026
Apache Syncope: Non-recursive Any search could skip Realms restrictions
Sep 14, 2026
Apache Syncope: Nested secrets leak cleartext into audit records readable
Sep 14, 2026
Apache Syncope: Incomplete authorization checks for Group members deprovisioning
Sep 14, 2026
Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search
Sep 14, 2026
Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values
Sep 14, 2026
Apache Syncope: Groovy Sandbox escape for empty CommandArgs
Sep 14, 2026
Apache Syncope: ClientApp update entitlement not effective
Sep 14, 2026
Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist
Sep 14, 2026
Apache Syncope: Unauthenticated reflected XSS in Console and Enduser
Sep 14, 2026
Apache Syncope: Privilege escalation for admin user via JWT authentication
Sep 14, 2026
Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user
Sep 14, 2026
Apache Syncope: SQL injection via sort parameter in Task search
Sep 14, 2026
Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
Sep 14, 2026
Apache Syncope: AES Secret Key disclosure via log output
Sep 14, 2026
Apache Syncope: JWT subject spoofing
Sep 14, 2026
Apache Syncope: SRA OAuth2 JWT signature verification bypass
Sep 14, 2026
Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check
Jul 20, 2026
Apache Syncope: User self-service privilege escalation
Jul 20, 2026
Apache Syncope: SQL injection vulnerability in Audit Events search
Jul 20, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-73191 | Apache Syncope: CAS service URL injection via Forwarded HTTP headers | MEDIUM | 0.31% | Sep 14, 2026 |
| CVE-2026-73195 | Apache Syncope: CSV export spreadsheet formula injection | HIGH | 0.37% | Sep 14, 2026 |
| CVE-2026-73236 | Apache Syncope: Cross-Realm authorization bypass in delegated administration | HIGH | 0.36% | Sep 14, 2026 |
| CVE-2026-73370 | Apache Syncope: Cross-Realm boundaries reconciliation bypass | CRITICAL | 0.51% | Sep 14, 2026 |
| CVE-2026-73178 | Apache Syncope: JWT Access Token takeover | HIGH | 0.43% | Sep 14, 2026 |
| CVE-2026-73470 | Apache Syncope: Delegating users can grant unowned Roles | CRITICAL | 0.51% | Sep 14, 2026 |
| CVE-2026-73579 | Apache Syncope: Non-recursive Any search could skip Realms restrictions | CRITICAL | 0.51% | Sep 14, 2026 |
| CVE-2026-75015 | Apache Syncope: Nested secrets leak cleartext into audit records readable | MEDIUM | 0.39% | Sep 14, 2026 |
| CVE-2026-75030 | Apache Syncope: Incomplete authorization checks for Group members deprovisioning | CRITICAL | 0.62% | Sep 14, 2026 |
| CVE-2026-77051 | Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search | CRITICAL | 0.60% | Sep 14, 2026 |
| CVE-2026-73668 | Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values | CRITICAL | 0.51% | Sep 14, 2026 |
| CVE-2026-77147 | Apache Syncope: Groovy Sandbox escape for empty CommandArgs | MEDIUM | 0.45% | Sep 14, 2026 |
| CVE-2026-77181 | Apache Syncope: ClientApp update entitlement not effective | CRITICAL | 0.51% | Sep 14, 2026 |
| CVE-2026-77883 | Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist | MEDIUM | 0.39% | Sep 14, 2026 |
| CVE-2026-78318 | Apache Syncope: Unauthenticated reflected XSS in Console and Enduser | MEDIUM | 0.26% | Sep 14, 2026 |
| CVE-2026-78330 | Apache Syncope: Privilege escalation for admin user via JWT authentication | CRITICAL | 0.64% | Sep 14, 2026 |
| CVE-2026-78336 | Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user | HIGH | 0.43% | Sep 14, 2026 |
| CVE-2026-82232 | Apache Syncope: SQL injection via sort parameter in Task search | CRITICAL | 0.60% | Sep 14, 2026 |
| CVE-2026-86460 | Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence | CRITICAL | 0.60% | Sep 14, 2026 |
| CVE-2026-87779 | Apache Syncope: AES Secret Key disclosure via log output | HIGH | 0.43% | Sep 14, 2026 |
| CVE-2026-87785 | Apache Syncope: JWT subject spoofing | CRITICAL | 0.55% | Sep 14, 2026 |
| CVE-2026-87802 | Apache Syncope: SRA OAuth2 JWT signature verification bypass | CRITICAL | 0.28% | Sep 14, 2026 |
| CVE-2026-62418 | Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check | HIGH | 0.47% | Jul 20, 2026 |
| CVE-2026-62183 | Apache Syncope: User self-service privilege escalation | CRITICAL | 0.69% | Jul 20, 2026 |
| CVE-2026-57308 | Apache Syncope: SQL injection vulnerability in Audit Events search | CRITICAL | 0.83% | Jul 20, 2026 |
Showing 1 to 25 of 40 CVEs