Impact
Apache Syncope can allow a delegating user to create or update delegations that include Roles owned by other users or that belong to different Realm subtrees, giving the delegator or others higher privileges than intended. The vulnerability is a classic example of improper privilege management, enabling an attacker to grant themselves or other users roles they should not be able to access. This can lead to unauthorized access to protected resources and potentially to full administrative control over the system.
Affected Systems
Apache Syncope versions from 3.0.0‑M0 to 3.0.16, from 4.0.0‑M0 to 4.0.7, and from 4.1.0‑M0 to 4.1.2 are affected. The vendors listed are Apache Software Foundation: Apache Syncope. Users should verify whether any of these product versions are in use in their environment.
Risk and Exploitability
Although an EPSS score is not available, the nature of the flaw – allowing privileged role assignment – conveys a high potential for exploitation. Those who already possess delegation rights could exploit this weakness to gain unauthorized roles within and across realms. The flaw is not currently listed in the CISA KEV catalog, but the absence of a mitigation recommendation does not reduce its severity. Organizations should treat this as a high‑risk vulnerability, especially in deployments where many users can create delegations.
OpenCVE Enrichment