Description
Low-privileged authenticated Server-Side Request Forgery (SSRF)
vulnerability in Apache Syncope via Connectors and Resources check.



This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.



Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
Published: 2026-07-20
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Low‑privileged authenticated Server‑Side Request Forgery in Apache Syncope allows an attacker with limited user rights to cause the server to make arbitrary network requests through its Connectors and Resources check, potentially exposing internal resources or exfiltrating data. The weakness is identified as CWE‑918 and can undermine confidentiality and internal network isolation. The flaw requires authentication but does not need elevated privileges, making it possible for any authenticated user to exploit.

Affected Systems

Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.6, and 4.1.0‑M0 through 4.1.1 are affected, while upgrading to 4.0.7 or 4.1.2 removes the vulnerability.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity, yet the EPSS score of below 1% suggests a low likelihood of exploitation in the near term. However, the ability to force the server to reach any endpoint that Syncope can access poses a serious risk of internal network exposure and data leakage. The vulnerability is not listed in CISA KEV, so organizations should treat it as a high‑risk flaw until patched.

Generated by OpenCVE AI on July 30, 2026 at 19:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch by upgrading Apache Syncope to version 4.0.7 or 4.1.2.
  • Create a full backup of Syncope configuration files and databases prior to upgrading.
  • Restart the Syncope service after the upgrade to ensure the new code is running.

Generated by OpenCVE AI on July 30, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope

Mon, 20 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
Title Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check
Weaknesses CWE-918
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-21T14:57:00.487Z

Reserved: 2026-07-14T08:22:25.966Z

Link: CVE-2026-62418

cve-icon Vulnrichment

Updated: 2026-07-20T18:38:19.443Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T19:30:09Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)