Description
Incorrect Authorization vulnerability in Apache Syncope.



Delegated administration security checks are based on Realm hierarchy and enforced via prefix matches.
Due to incorrect implementation, two sibling Realms whose names begin with the same string cannot be correctly distinguished, resulting in incorrect authorization.





This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass leading to privilege escalation
Action: Patch now
AI Analysis

Impact

Apache Syn prefix matches. The implementation incorrectly treats sibling realms whose names share the same leading string as distinct, they should not control. That produces an authorization bypass that can elevate privileges from a delegated administrator to another realm's resources, compromising confidentiality and integrity of the data in that realm.

Affected Systems

The vulnerability exists in Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users should verify that the software they run falls within these ranges and that they are not using the patched releases 4.0.8 or 4.1.3.

Risk and Exploitability

The CVSS score of 7.5 classifies this as a high severity issue. The EPSS score is <1%, indicating a very low exploitation probability, but the lack of listed status in the CISA KEV catalog does not mitigate the risk of discovery. Attackers who maintain delegated administrative rights and can observe realm names that share a common prefix can manipulate the authorization checks to gain unintended access to another realm’s data. The flaw is exploitable without additional privileges beyond those granted to a delegated administrator, so the impact is significant but limited to the scope of delegated roles.

Generated by OpenCVE AI on September 21, 2026 at 00:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to at least release 4.0.8 or 4.1.3 where the prefix matching logic has been corrected.
  • Verify that no two sibling realms maintain names that begin with the same string; if necessary, rename one of the real‑s odd realms to eliminate ambiguous prefixes.
  • Review delegated administration policies to ensure that authorized admins are limited to the intended realms and that no cross‑realm privileges are granted unintentionally.

Generated by OpenCVE AI on September 21, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm hierarchy and enforced via prefix matches. Due to incorrect implementation, two sibling Realms whose names begin with the same string cannot be correctly distinguished, resulting in incorrect authorization. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: Cross-Realm authorization bypass in delegated administration
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:31:48.348Z

Reserved: 2026-08-11T15:38:51.151Z

Link: CVE-2026-73236

cve-icon Vulnrichment

Updated: 2026-09-14T18:09:02.984Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:08.817

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-73236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses