Impact
Apache Syn prefix matches. The implementation incorrectly treats sibling realms whose names share the same leading string as distinct, they should not control. That produces an authorization bypass that can elevate privileges from a delegated administrator to another realm's resources, compromising confidentiality and integrity of the data in that realm.
Affected Systems
The vulnerability exists in Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users should verify that the software they run falls within these ranges and that they are not using the patched releases 4.0.8 or 4.1.3.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high severity issue. The EPSS score is <1%, indicating a very low exploitation probability, but the lack of listed status in the CISA KEV catalog does not mitigate the risk of discovery. Attackers who maintain delegated administrative rights and can observe realm names that share a common prefix can manipulate the authorization checks to gain unintended access to another realm’s data. The flaw is exploitable without additional privileges beyond those granted to a delegated administrator, so the impact is significant but limited to the scope of delegated roles.
OpenCVE Enrichment