Impact
Thisitlements in Apache Syncope. An administrator who possesses a ClientApp's update entitlement cannot actually update the application, while the system incorrectly checks the create entitlement for both creation and update actions. Consequently, the lack of correct authorization logic can be used by an attacker with the create entitlement to perform updates on ClientApp objects, effectively bypassing intended permission boundaries. The flaw is identified as CWE-863.
Affected Systems
Affected deployments are Apache Syncope versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. All installations that rely on ClientApp entitlement management and are running any of these versions are potentially impacted.
Risk and Exploitability
No EPSS score is publicly available, and the vulnerability is not included in CISA's KEV catalog. The CVSS score is not disclosed, so the assessed severity cannot be precisely quantified from the provided data. However, the flaw exposes a clear authorization bypass that could allow privilege escalation for users with create entitlements, meaning attackers who have gained user-level or temporary create rights could potentially upgrade to update operations without proper authorization. The attack vector would likely involve legitimate use of the create entitlement, although no documented exploitation exists at the time of this analysis.
OpenCVE Enrichment