cbcvebase.
CVE-2026-73470
published 2026-09-14

CVE-2026-73470: Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for…

PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.51%
41.3th percentile
Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Affected

3 ranges
VendorProductVersion rangeFixed in
apache_software_foundationapache_syncope3.0.0-M0 – 3.0.16—
apache_software_foundationapache_syncope4.0.0-M0 – 4.0.7—
apache_software_foundationapache_syncope4.1.0-M0 – 4.1.2—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.