Description
Missing Authorization vulnerability in Apache Syncope.



An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities.





This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.


Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized group member deprovisioning
Action: Patch
AI Analysis

Impact

A missing authorization check in Apache Syncope allows a user who has task execution entitlements to add or remove members from any group, even if the user normally does not have group‑administration rights. The flaw permits mass (de)provisioning of group seats and therefore undermines the integrity of group membership controls.

Affected Systems

Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are affected. The vendor recommends upgrading to version 4.0.8 or 4.1.3, which contain the fix.

Risk and Exploitability

The vulnerability requires a user with existing task‑execution privileges; therefore exploitation is limited to insiders or compromised privileged accounts. No publicly available exploit code exists, and the issue is not listed in CISA’s KEV catalog. The EPSS score is not available, so the likelihood of exploitation remains uncertain but can only occur for users who possess the necessary administrative entitlements.

Generated by OpenCVE AI on September 14, 2026 at 21:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to version 4.0.8 or 4.1.3, which includes the security fix.
  • Restrict task execution entitlements to the minimum set of functions required for legitimate operations and audit group‑membership changes for anomalous activity.
  • Check the vendor’s website regularly for updates and patches.

Generated by OpenCVE AI on September 14, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: Incomplete authorization checks for Group members deprovisioning
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:25:52.804Z

Reserved: 2026-08-17T15:05:27.124Z

Link: CVE-2026-75030

cve-icon Vulnrichment

Updated: 2026-09-14T18:09:10.855Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:18:45.990

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-75030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T21:15:09Z

Weaknesses