Description
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.

An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information.

This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.

Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
Published: 2026-05-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An administrator with sufficient entitlements to create Derived Schemas can craft a malicious JEXL expression that allows any administrator who has user‑read privileges to retrieve security‑sensitive data about users, resulting in a confidentiality breach. The weakness lies in improper validation of JEXL expressions, classified as CWE‑202. The intended impact is unauthorized disclosure of user data, without modifying system state. It is inferred that the vulnerability requires the attacker to possess administrative entitlements for Derived Schema creation and user reading; it is not remotely exploitable from an external host.

Affected Systems

This issue affects Apache Syncope versions 3.0 through 3.0.16, 4.0 through 4.0.5, and 4.1.0. The vulnerability is present in all affected releases regardless of deployment size or configuration, provided the attacker holds the necessary schema‑creation and user‑read entitlements.

Risk and Exploitability

The EPSS score is not available, indicating either a low known exploitation rate or insufficient data. The vulnerability is not listed in the CISA KEV catalog. It carries a high potential impact due to the sensitive nature of the exposed data. The attacker must already have administrative privileges and sufficient rights to create derived schemas and read users, which represents a fairly high access requirement. Exploitation requires only internal administrative access; no external network interaction is required. It is inferred that the vulnerability is not remotely exploitable from outside the organization.

Generated by OpenCVE AI on May 25, 2026 at 16:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to version 4.0.6 or 4.1.1, which limits JEXL expression definitions and removes the flaw.
  • Review and tighten permissions for Derived Schema creation, ensuring only trusted administrators can create or modify schemas.
  • Configure the JEXL expression parser to enforce strict validation rules, limiting expression complexity and preventing the use of privileged functions.

Generated by OpenCVE AI on May 25, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope

Mon, 25 May 2026 15:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
Title Apache Syncope: JexlContextBuilder Information Disclosure
Weaknesses CWE-202
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-05-25T20:30:25.603Z

Reserved: 2026-04-30T06:10:34.810Z

Link: CVE-2026-42797

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T17:00:15Z

Weaknesses