Description
Insufficiently Protected Credentials vulnerability in Apache Syncope.

Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values.





This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.


Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality compromise
Action: Patch
AI Analysis

Impact

Audit events in Apache Syncope are recorded without masking sensitive information, allowing administrators to view cleartext credentials or other secrets that are attached to audit payloads. This flaw falls under CWE-522, indicating that credentials are not adequately protected during storage or transportation. The primary consequence is the exposure of confidential data to anyone with administrative access to the audit store, potentially facilitating credential theft or further compromise of systems that rely on those credentials.

Affected Systems

Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2 are vulnerable. Users of these releases should verify their version and plan a migration to a supported release.

Risk and Exploitability

The CVSS score of 4.9 reflects moderate risk primarily due to the requirement for administrator-level access to read audit logs. The EPSS score is <1%, and the vulnerability is not listed in CISA KEV, indicating no known active exploits at this time. The attack vector is inferred to be local or sub‑network based, relying on legitimate administrative privileges to retrieve unmasked audit records.

Generated by OpenCVE AI on September 21, 2026 at 00:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to version 4.0.8 or 4.1.3, which corrects the issue.
  • Review and adjust the audit configuration to mask or encrypt sensitive values before they are written to the configured store.
  • Restrict administrative access to audit stores or archival export capabilities to limit exposure of previously unmasked logs.

Generated by OpenCVE AI on September 21, 2026 at 00:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Mon, 14 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: Nested secrets leak cleartext into audit records readable
Weaknesses CWE-522
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:26:59.920Z

Reserved: 2026-08-17T13:08:21.241Z

Link: CVE-2026-75015

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:18:45.860

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-75015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials