Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope.

An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body.
These values can be then used to perform further REST requests, impersonating users with higher administration entitlements.





This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Token Disclosure & Impersonation
Action: Apply Patch
AI Analysis

Impact

An administrator with sufficient entitlements can use the REST API to retrieve a list of existing access tokens, including their signed JWT bodies. These tokens can then be reused to issue REST requests that impersonate users with higher administrative privileges, effectively exposing sensitive information and enabling privilege escalation. The weakness is a form of sensitive data exposure, specifically CWE-200.

Affected Systems

Apache Syncope is affected across multiple milestone releases. Versions from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2 all contain the flaw. Users must upgrade to the patched versions to eliminate this risk.

Risk and Exploitability

The flaw requires the attacker to possess or acquire administrative credentials to access the privileged REST endpoint. Once an admin role is obtained, the token listing can be exploited without additional conditions; the attacker can copy the signed JWT and use it to authenticate as a more privileged user. The CVSS score of 7.5 indicates high severity, while an EPSS score of less than 1% suggests low but nonzero likelihood of exploitation. The vulnerability is not in the CISA KEV catalog, but its potential for impersonation and credential abuse poses a significant risk in environments with high‑privilege accounts.

Generated by OpenCVE AI on September 21, 2026 at 00:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to version 4.0.8 or 4.1.3 where the token listing vulnerability is fixed.
  • Restrict or reconfigure the REST API so that only necessary roles can list access tokens; consider disabling the token enumeration capability if it is not required.
  • Perform an access‑control review to remove unnecessary high‑privilege accounts, ensuring only trusted administrators retain the ability to list tokens.

Generated by OpenCVE AI on September 21, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 14 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. These values can be then used to perform further REST requests, impersonating users with higher administration entitlements. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: JWT Access Token takeover
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:29:51.690Z

Reserved: 2026-08-11T10:15:37.051Z

Link: CVE-2026-73178

cve-icon Vulnrichment

Updated: 2026-09-14T18:08:59.042Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:18:45.067

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-73178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor