Description
Exposure of sensitive information through data queries vulnerability in Apache Syncope.

An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

A malicious JEXL expression can bypass the JexlContextBuilder name denylist in Apache Syncope, allowing an administrator with Derived Schemas entitlement to create expressions that, when evaluated by another user with User read privileges, expose sensitive LinkedAccount or Manager attributes, including potentially hashed credentials. Because the attacker must be a privileged administrator, the vulnerability is confined to users with existing administrative rights, but any such user can read confidential data they are not normally permitted to see.

Affected Systems

Apache Syncope deployments from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2 are affected. The recommendation is to upgrade to version 4.0.8 or 4.1.3, which contain the fix.

Risk and Exploitability

The CVSS of 4.9 indicates moderate severity. With an EPSS score of less than 1% and no listing in KEV, the likelihood of observed exploitation is low at present. The flaw can be used by any administrator who can create Derived Schemas to craft a JEXL expression; the expression will then be evaluated under a user with read access, allowing the attacker to read sensitive fields. The risk is primarily a confidentiality compromise of data stored in LinkedAccount or Manager objects; the vulnerability does not provide privilege escalation or denial of service beyond data exposure.

Generated by OpenCVE AI on September 21, 2026 at 00:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to version 4.0.8 or 4.1.3 to eliminate the JEXL denylist bypass.
  • Restrict creation of Derived Schemas to administrators who absolutely need this capability.
  • Remove or restrict exposure of LinkedAccount and Manager attributes from user schemas to limit the amount of sensitive data that could be accessed.

Generated by OpenCVE AI on September 21, 2026 at 00:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope

Mon, 14 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist
Weaknesses CWE-202
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:16:45.603Z

Reserved: 2026-08-21T16:15:31.747Z

Link: CVE-2026-77883

cve-icon Vulnrichment

Updated: 2026-09-14T18:09:15.988Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:18:46.740

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-77883

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-202

    Exposure of Sensitive Information Through Data Queries