Impact
The vulnerability is an incorrect privilege assignment in Apache Syncope’s internal JWT authentication. When the JWKS configuration for internal JWT authentication is disclosed (at least the protocol and key), an attacker can obtain admin privileges after successfully authenticating and possessing a valid low‑privilege JWT. This flaw allows an attacker to elevate privileges to an admin user.
Affected Systems
Affected systems are Apache Syncope deployments running versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. All installations using any of these versions are vulnerable; the vulnerability is independent of the underlying operating system.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests that exploitation has not been widespread yet, and the vulnerability is not listed in CISA’s KEV catalog. The attack scenario requires disclosure of the JWKS settings, a successful authentication to obtain a low‑privilege JWT, and then manipulation of that token to gain admin rights. The path is straightforward but necessitates knowledge or interception of JWKS data.
OpenCVE Enrichment