Executive brief
Apache Syncope, an open-source system for managing digital identities, is vulnerable to a security flaw where users with low-level access can trick the server into making unauthorized requests. This could allow an attacker to probe internal network services that are not normally accessible from the outside, potentially leading to further internal attacks or data exposure. Organizations using affected versions should upgrade to the latest releases to prevent unauthorized internal network scanning.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Apache Syncope within the Connectors and Resources check functionality. The flaw allows an authenticated user with low privileges to influence or control the destination of network requests made by the Syncope server. By exploiting this, an attacker can use the server as a proxy to scan internal network ports, interact with internal services, or bypass network segmentation. The vulnerability is tracked as CWE-918 and affects multiple branches of the 3.x and 4.x release cycles. Users are advised to upgrade to versions 4.0.7 or 4.1.2 to remediate the issue.
Affected products
- Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, 4.1.0-M0 through 4.1.1
Timeline
- 2026-07-20: disclosed: Initial public disclosure by Apache
- 2026-07-20: advisory: NVD record published