Junglewise Threat Intelligence

CVE-2026-42797: Apache Syncope information disclosure via malicious JEXL expression

CVE-2026-42797 · Severity: medium · CVSS 4.9 · Published 2026-05-25

Technologies: Apache Software Foundation Syncope. Vendors: Apache, Apache Software Foundation.

Executive brief

Apache Syncope, an open-source system for managing digital identities, is vulnerable to an information disclosure flaw. A malicious administrator with specific permissions can create specially crafted data rules that allow other users to view sensitive security information they should not be able to see. This could lead to the exposure of private user data or internal security details, potentially compromising the integrity of the identity management system.

Technical details

A vulnerability in Apache Syncope (specifically within the syncope-core-provisioning-api) allows for the exposure of sensitive information through data queries (CWE-202). The root cause is insufficient restriction of JEXL (Java Expression Language) expressions within Derived Schemas. An attacker with 'Derived Schema' entitlements can define a malicious JEXL expression that, when processed, exposes security-sensitive user data to any administrator possessing 'User read' entitlements. This is a network-based attack requiring high privileges. The issue is resolved in versions 4.0.6 and 4.1.1 by implementing stricter JEXL expression definitions.

Affected products

  • Apache Syncope 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0

Timeline

  • 2026-05-25: disclosed: Initial disclosure by Apache Software Foundation
  • 2026-05-26: advisory: GitHub Advisory published
  • 2026-06-30: patched: Advisory updated with reviewed status and patch confirmation

References

Related threats