Description
Improper Privilege Management vulnerability in Apache Syncope.





Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for.



This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.


Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

Apache Syncope can allow a delegating user to create or update delegations that include Roles owned by other users or that belong to different Realm subtrees, giving the delegator or others higher privileges than intended. The vulnerability is a classic example of improper privilege management, enabling an attacker to grant themselves or other users roles they should not be able to access. This can lead to unauthorized access to protected resources and potentially to full administrative control over the system.

Affected Systems

Apache Syncope versions from 3.0.0‑M0 to 3.0.16, from 4.0.0‑M0 to 4.0.7, and from 4.1.0‑M0 to 4.1.2 are affected. The vendors listed are Apache Software Foundation: Apache Syncope. Users should verify whether any of these product versions are in use in their environment.

Risk and Exploitability

Although an EPSS score is not available, the nature of the flaw – allowing privileged role assignment – conveys a high potential for exploitation. Those who already possess delegation rights could exploit this weakness to gain unauthorized roles within and across realms. The flaw is not currently listed in the CISA KEV catalog, but the absence of a mitigation recommendation does not reduce its severity. Organizations should treat this as a high‑risk vulnerability, especially in deployments where many users can create delegations.

Generated by OpenCVE AI on September 14, 2026 at 20:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to 4.0.8 or 4.1.3 or later, which contain the defect fix.
  • Immediately audit existing delegations for improperly assigned Roles or misplaced realm coverage and revoke any that violate ownership or realm boundaries.
  • Limit delegation creation rights to a minimal set of trusted administrators until the upgrade is applied, and monitor delegation creation activity for anomalous behavior.

Generated by OpenCVE AI on September 14, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 14 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: Delegating users can grant unowned Roles
Weaknesses CWE-269
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:28:54.807Z

Reserved: 2026-08-12T16:53:28.488Z

Link: CVE-2026-73470

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:18:45.190

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-73470

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T20:15:06Z

Weaknesses
  • CWE-269

    Improper Privilege Management