Impact
An administrator with sufficient entitlements can use the REST API to retrieve a list of existing access tokens, including their signed JWT bodies. These tokens can then be reused to issue REST requests that impersonate users with higher administrative privileges, effectively exposing sensitive information and enabling privilege escalation. The weakness is a form of sensitive data exposure, specifically CWE-200.
Affected Systems
Apache Syncope is affected across multiple milestone releases. Versions from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2 all contain the flaw. Users must upgrade to the patched versions to eliminate this risk.
Risk and Exploitability
The flaw requires the attacker to possess or acquire administrative credentials to access the privileged REST endpoint. Once an admin role is obtained, the token listing can be exploited without additional conditions; the attacker can copy the signed JWT and use it to authenticate as a more privileged user. The CVSS score of 7.5 indicates high severity, while an EPSS score of less than 1% suggests low but nonzero likelihood of exploitation. The vulnerability is not in the CISA KEV catalog, but its potential for impersonation and credential abuse poses a significant risk in environments with high‑privilege accounts.
OpenCVE Enrichment