Impact
The vulnerability arises from incomplete authorization checks performed by the Reconciliation service’s pull and push operations in Apache Syncope, a CWE‑863 Delegated Authorization weakness, allowing an administrator lacking proper entitlements to invoke these endpoints. This permits cross‑realm data manipulation and effectively bypasses intended security boundaries, leading to unauthorized access to user information and configuration settings across distinct realms.
Affected Systems
Apache Syncope is affected from version 3.0.0‑M0 through 3.0.16, from 4.0.0‑M0 through 4.0.7, and from 4.1.0‑M0 through 4.1.2. The vendor recommends upgrading to version 4.0.8 or 4.1.3, which contain the fix.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the KEV. The CVSS score of 9.8 reflects a high‑risk severity, high‑risk privilege escalation. The likely attack vector is exploitation of Reconciliation service’s API by a user who presents, enabling cross‑realm changes or data exposure.
OpenCVE Enrichment