Impact
A missing authorization check in Apache Syncope allows a user who has task execution entitlements to add or remove members from any group, even if the user normally does not have group‑administration rights. The flaw permits mass (de)provisioning of group seats and therefore undermines the integrity of group membership controls.
Affected Systems
Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are affected. The vendor recommends upgrading to version 4.0.8 or 4.1.3, which contain the fix.
Risk and Exploitability
The vulnerability requires a user with existing task‑execution privileges; therefore exploitation is limited to insiders or compromised privileged accounts. No publicly available exploit code exists, and the issue is not listed in CISA’s KEV catalog. The EPSS score is not available, so the likelihood of exploitation remains uncertain but can only occur for users who possess the necessary administrative entitlements.
OpenCVE Enrichment