Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope.





When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-supplied forwarded HTTP headers.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect via Untrusted Service URL
Action: Upgrade
AI Analysis

Impact

The vulnerability exists in Apache Syncope when configured for CAS authentication. The software constructs the target CAS instance URL by blindly trusting forwarded HTTP headers supplied by the client. An attacker can manipulate these headers to inject an arbitrary service URL, causing the Syncope application to redirect end users to an attacker‑controlled site. This is a classic open‑redirect flaw (CWE‑601) that can be leveraged for phishing or other malicious redirects.

Affected Systems

Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are affected. The product is vulnerable until upgraded to version 4.0.8 or 4.1.3, which contain the fix.

Risk and Exploitability

Based on the description, it is inferred that the attack vector is client‑supplied forwarded headers, allowing attackers to manipulate requests via a web browser or crafted HTTP requests. The CVSS score is 6.1, and the EPSS score is < 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA KEV. Despite the lack of quantified metrics, the flaw is exploitable in open‑access scenarios. The impact of an open redirect is to compromise the trust boundary between users and the application, facilitating phishing, credential theft, and session hijacking.

Generated by OpenCVE AI on September 21, 2026 at 00:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade8 for the 4.0 branch or 4.1.3 for the 4.1 branch, which resolve the forward header bypass.
  • If an upgrade cannot be performed immediately, configure Syncope to ignore or strip client‑supplied forwarded headers during CAS authentication to prevent the URL from being constructed from untrusted data.
  • Validate that any CAS service URL used for red allowing the redirect.

Generated by OpenCVE AI on September 21, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-supplied forwarded HTTP headers. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: CAS service URL injection via Forwarded HTTP headers
Weaknesses CWE-601
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:32:54.329Z

Reserved: 2026-08-11T11:03:09.545Z

Link: CVE-2026-73191

cve-icon Vulnrichment

Updated: 2026-09-14T18:09:00.348Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:08.450

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-73191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')