Description
Missing Authorization vulnerability in Apache Syncope.



An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities.





This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.


Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized group member deprovisioning
Action: Patch
AI Analysis

Impact

A missing authorization check in Apache Syncope allows a user with task execution entitlements to add or remove any group members, regardless of the user’s normal group‑administration rights. This flaw, classified as CWE‑862 (Missing Authorization), undermines the integrity of group membership controls and could result in widespread mis‑assignment of access.

Affected Systems

Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are affected. The vendor recommends upgrading to 4.0.8 or 4.1.3 to obtain the fix.

Risk and Exploitability

The vulnerability requires a user with existing task‑execution privileges, so exploitation is limited to insiders or compromised privileged accounts. The CVSS score of 9.8 indicates high severity, but the EPSS score of <1% shows a very low probability of exploitation. The issue is not listed in CISA KEV, and no publicly available exploit code is known. Based on the description, it is inferred that exploitation would be difficult and confined to users who already possess the necessary administrative entitlements.

Generated by OpenCVE AI on September 21, 2026 at 01:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to version 4.0.8 or 4.1.3 to apply the security fix.
  • Restrict task execution entitlements to the minimum required functions to limit the scope of potential abuse.
  • Audit and monitor group‑membership changes for anomalous activity to detect unauthorized modifications.

Generated by OpenCVE AI on September 21, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: Incomplete authorization checks for Group members deprovisioning
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:25:52.804Z

Reserved: 2026-08-17T15:05:27.124Z

Link: CVE-2026-75030

cve-icon Vulnrichment

Updated: 2026-09-14T18:09:10.855Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:18:45.990

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-75030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses