cbcvebase.

Apache Software Foundation Apache Syncope vulnerabilities

40 known vulnerabilities affecting apache_software_foundation/apache_syncope.

Total CVEs
40
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH11MEDIUM12

Vulnerabilities

Page 2 of 2
CVE-2026-62418P3HIGHCVSS 8.1≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.6+1 more2026-07-20
CVE-2026-62418 [HIGH] CWE-918 CVE-2026-62418: Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
nvd
CVE-2025-65998P3HIGHCVSS 7.5≥ 2.1, ≤ 2.1.14≥ 3.0, ≤ 3.0.14+1 more2025-11-24
CVE-2025-65998 [HIGH] CWE-321 CVE-2025-65998: Apache Syncope can be configured to store the user password values in the internal database with AES Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option. When AES is configured, the default key value, hard-coded in the source code, is always used. This allows a malicious attacker, once obtained access to the internal database content, to reconstruct th
nvd
CVE-2026-42782P3HIGHCVSS 7.2≥ 3.0, ≤ 3.0.16≥ 4.0, ≤ 4.0.5+1 more2026-05-25
CVE-2026-42782 [HIGH] CWE-653 CVE-2026-42782: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with a Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.
cvelistv5nvd
CVE-2026-73178P3HIGHCVSS 7.5≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-73178 [HIGH] CWE-200 CVE-2026-73178: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An admi Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. These values can be then used to perform further REST requests, impersonating users with higher administration entitlemen
nvd
CVE-2026-78336P3HIGHCVSS 7.5≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-78336 [HIGH] CWE-201 CVE-2026-78336: Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authentica Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller. This issue aff
nvd
CVE-2026-73236P3HIGHCVSS 7.5≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-73236 [HIGH] CWE-863 CVE-2026-73236: Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm hierarchy and enforced via prefix matches. Due to incorrect implementation, two sibling Realms whose names begin with the same string cannot be correctly distinguished, resulting in incorrect authorization. This issue affects Apache Sy
nvd
CVE-2026-87779P3HIGHCVSS 7.5≥ 3.0.15, ≤ 3.0.16≥ 4.0.3, ≤ 4.0.7+1 more2026-09-14
CVE-2026-87779 [HIGH] CWE-532 CVE-2026-87779: Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The resulting key value is logged. This issue affects Apache Syncope: from 3.0.15 through 3.0.16, from 4.0.3 through 4.0.7, from 4.1.0-M0
nvd
CVE-2026-73195P3HIGHCVSS 7.3≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-73195 [HIGH] CWE-116 CVE-2026-73195: Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet formula payload in one of their own plain attributes. When such users are included in a CSV export and the generated CSV file is opened by a spreadsheet application, the formula may be executed. This issue affects Apache Syncope: from 3
nvd
CVE-2018-17186P3HIGHCVSS 7.2vApache Syncope releases prior to 2.0.11 and 2.1.22018-11-06
CVE-2018-17186 [HIGH] CWE-611 CVE-2018-17186: An administrator with workflow definition entitlements can use DTD to perform malicious operations, An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
nvd
CVE-2026-77147P3MEDIUMCVSS 6.5≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-77147 [MEDIUM] CWE-94 CVE-2026-77147: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An admin Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their CommandArgs static implementation, bypassing the Groovy security sandbox. This issue affects Apache Syncope: from 3.0
nvd
CVE-2026-23794P3MEDIUMCVSS 6.8≥ 3.0, ≤ 3.0.15≥ 4.0, ≤ 4.0.32026-02-03
CVE-2026-23794 [MEDIUM] CWE-79 CVE-2026-23794: Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials. This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3. Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fi
nvd
CVE-2026-23795P4MEDIUMCVSS 4.9≥ 3.0, ≤ 3.0.15≥ 4.0, ≤ 4.0.32026-02-03
CVE-2026-23795 [MEDIUM] CWE-611 CVE-2026-23795: Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An ad Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby causing sensitive data leakage occurs. This issue affects Apache Syncope: from 3.0 through 3.0
nvd
CVE-2026-73191P4MEDIUMCVSS 6.1≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-73191 [MEDIUM] CWE-601 CVE-2026-73191: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the S URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-supplied forwarded HTTP headers. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4
nvd
CVE-2026-77883P4MEDIUMCVSS 4.9≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-77883 [MEDIUM] CWE-202 CVE-2026-77883: Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administ Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information
nvd
CVE-2026-75015P4MEDIUMCVSS 4.9≥ 3.0.0-M0, ≤ 3.0.16≥ 4.0.0-M0, ≤ 4.0.7+1 more2026-09-14
CVE-2026-75015 [MEDIUM] CWE-522 CVE-2026-75015: Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to th Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0
nvd
CVE-2024-45031P4MEDIUMCVSS 6.1≥ 2.1, ≤ 2.1.14≥ 3.0, ≤ 3.0.82024-10-24
CVE-2024-45031 [MEDIUM] CWE-79 CVE-2024-45031: When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanit When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made it possible to inject stored XSS payloads which would trigger for other users during ordinary usage of the application. XSS payloads could also be injected in Syncope Enduser when editing “Personal Information” or “User Requests”: su
nvd
CVE-2026-42797P4MEDIUMCVSS 4.9≥ 3.0, ≤ 3.0.16≥ 4.0, ≤ 4.0.5+1 more2026-05-25
CVE-2026-42797 [MEDIUM] CWE-202 CVE-2026-42797: Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administ Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information. This issue affects Apache Sync
cvelistv5nvd
CVE-2026-78318P4MEDIUMCVSS 6.1≥ 4.0.4, ≤ 4.0.7≥ 4.1.0-M0, ≤ 4.1.22026-09-14
CVE-2026-78318 [MEDIUM] CWE-79 CVE-2026-78318: Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HTML tags with unsafe JS inline, via malicious HTTP link generation. This issue affects Apache Syncope: from 4.0.4 t
nvd
CVE-2024-38503P4MEDIUMCVSS 5.4≥ 2.1, ≤ 2.1.14≥ 3.0, ≤ 3.0.72024-07-22
CVE-2024-38503 [MEDIUM] CWE-79 CVE-2024-38503: When editing a user, group or any object in the Syncope Console, HTML tags could be added to any tex When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.
nvd
CVE-2018-17184P4MEDIUMCVSS 5.4vApache Syncope releases prior to 2.0.11 and 2.1.22018-11-06
CVE-2018-17184 [MEDIUM] CWE-79 CVE-2018-17184: A malicious user with enough administration entitlements can inject html-like elements containing Ja A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.
nvd
Apache Software Foundation Apache Syncope vulnerabilities | cvebase