Apache Software Foundation Apache Syncope vulnerabilities
40 known vulnerabilities affecting apache_software_foundation/apache_syncope.
Total CVEs
40
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH11MEDIUM12
Vulnerabilities
Page 1 of 2
CVE-2018-1321P3HIGHCVSS 7.2PoCvReleases prior to 1.2.11, Releases prior to 2.0.8vThe unsupported Releases 1.0.x, 1.1.x may be also affected.2018-03-20
CVE-2018-1321 [HIGH] CWE-20 CVE-2018-1321: An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x
An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can use XSL Transformations (XSLT) to perform malicious operations, including but not limited to file read, file write, and code execution.
nvd
CVE-2026-87785P2CRITICALCVSS 9.1≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-87785 [CRITICAL] CWE-290 CVE-2026-87785: Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS setti
Authentication bypass by spoofing vulnerability in Apache Syncope.
When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a successful authentication and obtaining a valid JWT.
This issue affects Apache Syncope: from 3.0.0-M0 thro
nvd
CVE-2026-57308P2CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.6+1 more2026-07-20
CVE-2026-57308 [CRITICAL] CWE-89 CVE-2026-57308: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through
nvd
CVE-2026-77051P2CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-77051 [CRITICAL] CWE-89 CVE-2026-77051: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized entityKey and opEvent parameters.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, fro
nvd
CVE-2026-82232P2CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-82232 [CRITICAL] CWE-89 CVE-2026-82232: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort clauses for Task search.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.
nvd
CVE-2026-78330P2CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-78330 [CRITICAL] CWE-266 CVE-2026-78330: Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings f
Incorrect privilege assignment vulnerability in Apache Syncope.
When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT.
This issue affects Apache Syncope: from 3.0.0-M
nvd
CVE-2026-53421P2CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.6+1 more2026-07-20
CVE-2026-53421 [CRITICAL] CWE-653 CVE-2026-53421: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0
nvd
CVE-2018-1322P3MEDIUMCVSS 4.9PoCvReleases prior to 1.2.11, Releases prior to 2.0.8vThe unsupported Releases 1.0.x, 1.1.x may be also affected.2018-03-20
CVE-2018-1322 [MEDIUM] CWE-200 CVE-2018-1322: An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
nvd
CVE-2025-57738P2HIGHCVSS 7.2≥ 2.1, ≤ 2.1.14≥ 3.0, ≤ 3.0.13+1 more2025-10-20
CVE-2025-57738 [HIGH] CWE-653 CVE-2025-57738: Apache Syncope offers the ability to extend / customize the base behavior on every deployment by all
Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload.
Such a feature has been av
nvd
CVE-2026-53405P2CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.6+1 more2026-07-20
CVE-2026-53405 [CRITICAL] CWE-653 CVE-2026-53405: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with a
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no
nvd
CVE-2026-63071P2CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.6+1 more2026-07-20
CVE-2026-63071 [CRITICAL] CWE-653 CVE-2026-63071: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with a
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, from 4.1.0-M0
nvd
CVE-2026-62183P2CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.6+1 more2026-07-20
CVE-2026-62183 [CRITICAL] CWE-269 CVE-2026-62183: Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow
Improper Privilege Management vulnerability in Apache Syncope.
When:
* the all-Java user workflow adapter is configured, or
* the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests
the following scenario could happen.
A REST API call can allow the
nvd
CVE-2026-86460P2CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-86460 [CRITICAL] CWE-89 CVE-2026-86460: Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search condi
Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
nvd
CVE-2026-73579P2CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-73579 [CRITICAL] CWE-863 CVE-2026-73579: Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into
Incorrect Authorization vulnerability in Apache Syncope.
Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration.
An important component of such transformation is the Realms filter, which ensures that the search results are matching the requester's permissions.
For
nvd
CVE-2026-73470P3CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-73470 [CRITICAL] CWE-269 CVE-2026-73470: Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or up
Improper Privilege Management vulnerability in Apache Syncope.
Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2
nvd
CVE-2026-75030P3CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-75030 [CRITICAL] CWE-862 CVE-2026-75030: Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entit
Missing Authorization vulnerability in Apache Syncope.
An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
User
nvd
CVE-2026-77181P3CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-77181 [CRITICAL] CWE-863 CVE-2026-77181: Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update
Incorrect Authorization vulnerability in Apache Syncope.
An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update operations on ClientApp.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7,
nvd
CVE-2026-73668P3CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-73668 [CRITICAL] CWE-863 CVE-2026-73668: Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitle
Incorrect Authorization vulnerability in Apache Syncope.
An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another Realm and thus be able to effectively duplicate such Connector instance into the Realm they have administration rights
nvd
CVE-2026-87802P3CRITICALCVSS 9.1≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-87802 [CRITICAL] CWE-347 CVE-2026-87802: Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is con
Improper verification of cryptographic signature vulnerability in Apache Syncope.
When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16,
nvd
CVE-2026-73370P3CRITICALCVSS 9.8≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-73370 [CRITICAL] CWE-863 CVE-2026-73370: Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks
Incorrect Authorization vulnerability in Apache Syncope.
Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate entitlements.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1
nvd
1 / 2Next →