Impact
The vulnerability arises from incomplete authorization checks performed by the Reconciliation service’s pull and push operations in Apache Syncope, allowing an administrator lacking proper entitlements to invoke these endpoints. This permits cross‑realm data manipulation and effectively bypasses intended security boundaries, leading to unauthorized access to user information and configuration settings across distinct realms.
Affected Systems
Apache Syncope is affected from version 3.0.0‑M0 through 3.0.16, from 4.0.0‑M0 through 4.0.7, and from 4.1.0‑M0 through 4.1.2. The vendor recommends upgrading to version 4.0.8 or 4.1.3, which contain the fix.
Risk and Exploitability
EPSS information is not available and the vulnerability is not listed in the C the data, the ability to bypass delegated administration represents a high‑risk privilege escalation. The likely attack vector is exploitation of the Reconciliation service’s API by a user who presents, enabling cross‑realm changes or data exposure.
OpenCVE Enrichment