Impact
Thisitlements in Apache Syncope. An administrator who possesses a ClientApp's update entitlement cannot actually update the application, while the system incorrectly checks the create entitlement for both creation and usedApp objects, effectively bypassing intended permission boundaries. The flaw is identified as CWE-863.
Affected Systems
Affected deployments are Apache Syncope versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. All installations that rely on ClientApp entitlement management and are running any of these versions are potentially impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, underscoring a high likelihood of successful exploitation. The EPSS score of 0.00477 (< 1%) indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The flaw exposes a clear authorization bypass that could allow privilege escalation for users with create entitlements, meaning attackers who have gained user‑level or temporary create rights could potentially upgrade to update operations without proper authorization. The likely attack vector involves legitimate use of the create entitlement, although no documented exploitation exists at the time of this analysis.
OpenCVE Enrichment