CVE-2026-42797
published 2026-05-25CVE-2026-42797: Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can…
PriorityP426medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.44%
35.3th percentile
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information.
This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.
Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | syncope | — | — |
| apache | syncope | 3.0.0 – 3.0.16 | — |
| apache | syncope | >= 4.0.0 < 4.0.6 | 4.0.6 |
| apache_software_foundation | apache_syncope | 3.0 – 3.0.16 | — |
| apache_software_foundation | apache_syncope | 4.0 – 4.0.5 | — |
| apache_software_foundation | apache_syncope | 4.1 – 4.1.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vr35-jm2f-8wg2: Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope
ghsa_unreviewed·2026-05-26
CVE-2026-42797 [MEDIUM] CWE-202 GHSA-vr35-jm2f-8wg2: Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information.
This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.
Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
GHSA
Apache Syncope Vulnerable to Exposure of Sensitive Information Through Data Queries
ghsa·2026-05-26
CVE-2026-42797 [MEDIUM] CWE-202 Apache Syncope Vulnerable to Exposure of Sensitive Information Through Data Queries
Apache Syncope Vulnerable to Exposure of Sensitive Information Through Data Queries
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information.
This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.
Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
CVEList
Apache Syncope: JexlContextBuilder Information Disclosure
cvelistv5·2026-05-25
CVE-2026-42797 CWE-202 Apache Syncope: JexlContextBuilder Information Disclosure
Apache Syncope: JexlContextBuilder Information Disclosure
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information.
This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.
Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
VulDB
Apache Syncope up to 3.0.16/4.0.5/4.1.0 JEXL information exposure (EUVD-2026-31702)
vuldb·2026-05-25
CVE-2026-42797 [LOW] Apache Syncope up to 3.0.16/4.0.5/4.1.0 JEXL information exposure (EUVD-2026-31702)
A vulnerability was found in Apache Syncope up to 3.0.16/4.0.5/4.1.0. It has been declared as problematic. This affects an unknown part of the component JEXL Handler. The manipulation results in exposure of sensitive information through data queries.
This vulnerability is reported as CVE-2026-42797. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-25
Published