Impact
A missing authorization check in Apache Syncope allows a user with task execution entitlements to add or remove any group members, regardless of the user’s normal group‑administration rights. This flaw, classified as CWE‑862 (Missing Authorization), undermines the integrity of group membership controls and could result in widespread mis‑assignment of access.
Affected Systems
Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are affected. The vendor recommends upgrading to 4.0.8 or 4.1.3 to obtain the fix.
Risk and Exploitability
The vulnerability requires a user with existing task‑execution privileges, so exploitation is limited to insiders or compromised privileged accounts. The CVSS score of 9.8 indicates high severity, but the EPSS score of <1% shows a very low probability of exploitation. The issue is not listed in CISA KEV, and no publicly available exploit code is known. Based on the description, it is inferred that exploitation would be difficult and confined to users who already possess the necessary administrative entitlements.
OpenCVE Enrichment