Impact
Search requests in Apache Syncope are translated into database or search engine queries. For non-recursive searches the Realms filter that normally restricts results to the requester's authorized data can be rendered empty, effectively removing the authorization check. This allows an attacker to retrieve any data the system holds, regardless of the requested permission scope.
Affected Systems
Apache Software Foundation’s Apache Syncope is affected. Versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2 are vulnerable. Users of these releases should verify their product version and consult the vendor for updates.
Risk and Exploitability
The exploit requires only the ability to submit a non-recursive search request. No special privilege or further attack vector is required beyond that capability. While the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog, indicating it may not have known exploitation yet. Nonetheless, the potential to obtain unrestricted data makes patching a high priority.
OpenCVE Enrichment