Description
Insertion of sensitive information into sent data vulnerability in Apache Syncope.



Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller.



This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.



Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure of client secrets
Action: Apply Patch
AI Analysis

Impact

An authenticated user can query the list of OpenID Connect providers configured for Apache Syncope’s SSO console and end‑user interfaces. The API response contains the full configuration for each provider, including client secrets, regardless of the caller’s entitlement. Consequently, sensitive credentials are exposed to any user who can log into Syncope, allowing an attacker to recover secrets that could be used to forge authentication tokens or compromise downstream services that rely on those providers.

Affected Systems

The vulnerability affects Apache Software Foundation’s Apache Syncope. Versions from 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are vulnerable. The fix is included in version 4.0.8 and 4.1.3, which should be used for remediation.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score is less than 1%, suggesting low likelihood of public exploitation to date. However, because the attacker only needs to be an authenticated Syncope user, the risk remains significant for organizations that provide broad console access without further checks. The disclosure of client secrets could be leveraged to impersonate OAuth clients or to compromise applications that rely on the same identity provider.

Generated by OpenCVE AI on September 21, 2026 at 00:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to version 4.0.8 or later, or 4.1.3 or later, which removes the secret disclosure from API responses.
  • If an upgrade cannot be performed immediately, restrict the OIDC provider list API to users with higher‑level privileges and ensure that ordinary authenticated users cannot request provider information.
  • Continuously monitor audit logs for anomalous API activity that may indicate reconnaissance or abuse of the provider list endpoint.

Generated by OpenCVE AI on September 21, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user
Weaknesses CWE-201
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:21:38.676Z

Reserved: 2026-08-24T10:16:14.145Z

Link: CVE-2026-78336

cve-icon Vulnrichment

Updated: 2026-09-14T18:09:19.843Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:18:47.250

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-78336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T08:30:17Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data